Open cardosec

Case 6F4411 · AI security · L3 Applied

OWASP LLM Top 10 Threat Modeling

Practise as: Explain it · Deep dive
  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Use the list (2025 edition) as a threat-modeling checklist of app-level LLM risks, not a compliance standard to certify against.
  2. Plain chatbot: prompt injection, sensitive info disclosure, system prompt leakage, misinformation and cost abuse dominate.
  3. RAG adds poisoned or ACL-blind retrieval (vector/embedding weaknesses); agents add excessive agency, turning injection into action.
  4. Prompt injection cannot be fully patched: instructions and data share one channel, so assume it succeeds and contain the blast radius.
  5. Contain: least-privilege tools, human approval for consequential actions, and treat model output as untrusted input downstream.

If the interviewer pushes back

  • Which two items would you prioritize for a customer-facing RAG chatbot with no tools, and why?
  • Where does the list fall short for multi-step agents, and what would you add (e.g. MITRE ATLAS techniques)?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.