OWASP/wstg

Proposal: Add a New Chapter for Testing LLM Applications

开放

#1,447 创建于 2026年7月26日

 (3 条评论) (0 个反应) (0 位负责人) (1,624 个派生)github user discovery
help wantednew

仓库指标

星标
 (9,439 个星标)
PR 合并指标
 (平均合并 24天 19小时) (30 天内合并 22 个 PR)

描述

I'd like to propose adding a new chapter to the WSTG, tentatively titled 4.13 Testing LLM Applications.

As Generative AI and Large Language Models (LLMs) are increasingly integrated into web applications, the WSTG currently lacks dedicated guidance for assessing these features from a web application penetration testing perspective.

This chapter would provide practical testing guidance aligned with the OWASP Top 10 for LLM Applications.

Proposed initial structure:

  • 4.13.1 Testing for Prompt Injection (Direct and Indirect)

  • 4.13.2 Testing for Sensitive Information Disclosure

  • 4.13.3 Testing for Insecure Output Handling

  • 4.13.4 Testing for Excessive Agency and Tool Abuse

  • Assign me, please!

贡献者指南