Skip to content

Add LLM element class with 8 threat definitions#316

Open
izar wants to merge 1 commit intoOWASP:masterfrom
izar:LLM
Open

Add LLM element class with 8 threat definitions#316
izar wants to merge 1 commit intoOWASP:masterfrom
izar:LLM

Conversation

@izar
Copy link
Collaborator

@izar izar commented Feb 24, 2026

Introduce an LLM class derived from Asset to model Large Language Model usage in threat models, covering third-party APIs, self-hosted models, and autonomous agents. Includes 8 OWASP-aligned threats (LLM01-LLM08) for prompt injection, data leakage, training data poisoning, excessive agency, code execution, jailbreaking, and information disclosure.

Introduce an LLM class derived from Asset to model Large Language Model
usage in threat models, covering third-party APIs, self-hosted models,
and autonomous agents. Includes 8 OWASP-aligned threats (LLM01-LLM08)
for prompt injection, data leakage, training data poisoning, excessive
agency, code execution, jailbreaking, and information disclosure.

Co-Authored-By: Claude Opus 4.6 <noreply@anthropic.com>
@izar izar requested review from colesmj and nineinchnick February 24, 2026 15:55
@izar izar self-assigned this Feb 24, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant