OWASP LLM Risk Battlecards
Recall practical responses to common LLM application security objections.
Prompt injection What if a retrieved document tells the model to ignore instructions? RAG assistant with user-uploaded PDFs. Your line We treat retrieved text as untrusted input. The assistant has instruction separation, injection evals, no sensitive export tool, and logging for instruction-like chunks. Do not answer only with "the system prompt says not to." That is a prompt-level control, not application defense. The response names boundary, permission, test, and monitoring controls. Excessive agency Agent permissions: reflex or move? The control should live in tool design and approval flow, not only in the model instruction. Overreliance What stops users from trusting…
Sign up free — one personalized lesson every day, matched to your role and goals.
Already have an account? Sign in