You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Update project structure to reflect OWASP GenAI Security Project integration
- Update README.md to reflect project as subproject of OWASP GenAI Security Project
- Update CONTRIBUTING.md to direct to centralized contribution guidelines
- Update index.md with new mission statement and project evolution
- Update project status badge from Lab to Flagship Status
- Remove outdated wiki references and direct to main project site
- Add Sandy Dunn to leaders.md
- Remove Autumn Moulder from CoreTeam.md
- Update changes.md with version 2.0.0 entry
This update aligns the repository with the broader OWASP GenAI Security Project structure and provides clear direction to the main project site at genai.owasp.org
Thank you for your interest in contributing to an OWASP project. We welcome all contributions and appreciate your efforts to improve our projects.
3
+
Thank you for your interest in contributing to the OWASP Top 10 for Large Language Model Applications! We are a community-driven project and welcome all contributors, regardless of their background or experience level.
4
+
5
+
## Community-Driven Project
6
+
7
+
The OWASP Top 10 for LLM Applications is an open source effort that thrives on community collaboration. We welcome all expert ideas, contributions, suggestions, and remarks from security professionals, researchers, developers, and anyone passionate about AI security.
4
8
5
9
## Getting Started
6
10
7
-
We are managing contributions to the OWASP Top 10 for Large Language Model Applications through the wiki feature of our GitHub repository. You can find full directions on how to get involved [here](https://github.com/OWASP/www-project-top-10-for-large-language-model-applications/wiki).
11
+
For comprehensive contributor guidelines, including information about our various projects and initiatives, please visit our main project site: **[https://genai.owasp.org/contribute/](https://genai.owasp.org/contribute/)**
12
+
13
+
## Style Guidelines
8
14
9
15
Please make sure to consult the [Style Guide](./documentation/style/README.md) to ensure consistent styling with your contributions.
16
+
17
+
## Join Our Community
18
+
19
+
- Join our bi-weekly sync meetings
20
+
- Participate in our Slack channels for discussions
21
+
- Contribute to translations, publishing, data gathering, and more
22
+
- No OWASP membership required to contribute!
23
+
24
+
For more details on how to get involved, visit our [contribute page](https://genai.owasp.org/contribute/).
| Steve Wilson | Overall Lead |[Contrast Security](https://www.contrastsecurity.com/)|[LinkedIn](https://www.linkedin.com/in/wilsonsd/), [Twitter](https://twitter.com/virtualsteve), [GitHub](https://github.com/virtualsteve-star), [Book](https://www.contrastsecurity.com/hubfs/Cybersecurity%20and%20Artificial%20Intelligence%20Threats%20and%20Opportunities.pdf)|
11
10
| Mike Finch | Design Lead |[HackerOne](https://www.hackerone.com)|[LinkedIn](https://www.linkedin.com/in/mkfnch), [Twitter](https://twitter.com/mkfnch), [Personal](https://mkfnch.com)|
| Andy Smith | Expert ||[LinkedIn](https://www.linkedin.com/in/andysmith-uk/), [Twitter](https://twitter.com/rot169), [Bio](https://www.sans.org/profiles/andy-smith/)|
15
13
| David Rowe | Expert |[AWS](http://aws.amazon.com)|[LinkedIn](https://www.linkedin.com/in/davidprowe/), [Twitter](https://twitter.com/davidprowe/), [GitHub](https://github.com/davidprowe)|
Copy file name to clipboardExpand all lines: README.md
+11-5Lines changed: 11 additions & 5 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -6,12 +6,18 @@ OWASP Foundation Web Repository
6
6
# OWASP Top 10 for Large Language Model Applications
7
7
8
8
[](https://www.linkedin.com/posts/wilsonsd_announcing-the-version-2-project-its-time-activity-7157734167244378113-s2v2?utm_source=share&utm_medium=member_ios)
9
-
[](https://owasp.org/projects/)
9
+
[](https://owasp.org/projects/)
10
10
[](https://creativecommons.org/licenses/by-sa/4.0/)
Welcome to the official repository for the OWASP Top 10 for Large Language Model Applications!
14
14
15
+
## About This Repository
16
+
17
+
This repository contains the OWASP Top 10 for Large Language Model Applications, which is now housed under the comprehensive **OWASP GenAI Security Project**. The OWASP GenAI Security Project is a global, open-source initiative dedicated to identifying, mitigating, and documenting security and safety risks associated with generative AI technologies.
18
+
19
+
**Visit our main project site:**[genai.owasp.org](https://genai.owasp.org)
20
+
15
21
## Overview and Audience 🗣️
16
22
17
23
The OWASP Top 10 for Large Language Model Applications is a standard awareness document for developers and web application security. It represents a broad consensus about the most critical security risks to Large Language Model (LLM) applications. There are other ongoing frameworks both inside and outside of OWASP that are not to be confused with this project and is currently scoped towards only LLM Application Security.
@@ -24,17 +30,17 @@ The primary aim of this project is to provide a comprehensible and adoptable gui
24
30
25
31
## Mission Statement 🚀
26
32
27
-
Our mission is to make application security visible, so that people and organizations can make informed decisions about application security risks related to LLMs. While our list shares DNA with vulnerability types found in other OWASP Top 10 lists, we do not simply reiterate these vulnerabilities. Instead, we delve into these vulnerabilities’ unique implications when encountered in applications utilizing LLMs.
33
+
Our mission is to make application security visible, so that people and organizations can make informed decisions about application security risks related to LLMs. While our list shares DNA with vulnerability types found in other OWASP Top 10 lists, we do not simply reiterate these vulnerabilities. Instead, we delve into these vulnerabilities' unique implications when encountered in applications utilizing LLMs.
28
34
29
-
Our goal is to bridge the divide between general application security principles and the specific challenges posed by LLMs. The group’s goals include exploring how conventional vulnerabilities may pose different risks or be exploited in novel ways within LLMs and how developers must adapt traditional remediation strategies for applications utilizing LLMs.
35
+
Our goal is to bridge the divide between general application security principles and the specific challenges posed by LLMs. The group's goals include exploring how conventional vulnerabilities may pose different risks or be exploited in novel ways within LLMs and how developers must adapt traditional remediation strategies for applications utilizing LLMs.
30
36
31
37
## Contribution 👋
32
38
33
-
The first version of this list was contributed by Steve Wilson of Contrast Security. We encourage the community to contribute and help improve the project. If you have any suggestions, feedback or want to help improve the list, feel free to open an issue or send a pull request.
39
+
The first version of this list was contributed by Steve Wilson of Contrast Security. We encourage the community to contribute and help improve the project. If you have any suggestions, feedback or want to help improve the list, feel free to open an issue or send a pull request.
34
40
35
41
We have a working group channel on the [OWASP Slack](https://owasp.org/slack/invite), so please sign up and then join us on the #project-top10-llm channel.
36
42
37
-
Please hop over to [our wiki page](https://github.com/OWASP/www-project-top-10-for-large-language-model-applications/wiki) to collaborate on the project and stay up to date with the latest meetings and current roadmap.
43
+
**Learn how to contribute:**[https://genai.owasp.org/contribute/](https://genai.owasp.org/contribute/)
Copy file name to clipboardExpand all lines: changes.md
+17Lines changed: 17 additions & 0 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -4,6 +4,23 @@ All notable changes to the OWASP Top 10 for LLM Applications project will be doc
4
4
5
5
The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/), and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).
6
6
7
+
## [2.0.0] - 2025-01-27
8
+
9
+
### Changed
10
+
11
+
- Updated project documentation to reflect the OWASP Top 10 for Large Language Model Applications as a subproject of the comprehensive OWASP GenAI Security Project
12
+
- Updated README.md to include reference to the main project site at genai.owasp.org
13
+
- Updated CONTRIBUTING.md to direct contributors to the centralized contribution guidelines
14
+
- Updated index.md to reflect the project's evolution and growth into the OWASP GenAI Security Project
15
+
- Updated project status badge from "Lab Status" to "Flagship Status" in README.md
16
+
- Removed outdated wiki references and directed users to the main project site for comprehensive information
17
+
18
+
### Added
19
+
20
+
- Links to the main OWASP GenAI Security Project website and various initiative pages
21
+
- Updated mission statement reflecting the broader scope of the GenAI Security Project
22
+
- References to the project's growth to over 600 contributing experts from more than 18 countries
23
+
7
24
## [1.0.1] - 2023-08-26
8
25
9
26
[v1.1 Instructions for the Expert Group reference](https://github.com/OWASP/www-project-top-10-for-large-language-model-applications/wiki/v1_1-phases#v11-instructions-for-the-expert-group)
Copy file name to clipboardExpand all lines: index.md
+42-19Lines changed: 42 additions & 19 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -7,31 +7,54 @@ tags: example-tag
7
7
pitch: Aims to educate developers, designers, architects, managers, and organizations about the potential security risks when deploying and managing Large Language Models (LLMs)
8
8
---
9
9
10
-
The OWASP Top 10 for Large Language Model Applications Project aims to educate developers, designers, architects, managers, and organizations about the potential security risks when deploying and managing Large Language Models (LLMs) and Generative AI applications. The project provides a range of resources. Most notably the OWASP Top 10 list for LLM applications listing the top 10 most critical vulnerabilities often seen in LLM applications, highlighting their potential impact, ease of exploitation, and prevalence in real-world applications.
10
+
## About This Repository
11
11
12
-
Examples of vulnerabilities include prompt injections, data leakage, inadequate sandboxing, and unauthorized code execution, among others. The goal is to raise awareness of these vulnerabilities, suggest remediation strategies, and ultimately improve the security posture of LLM applications.
12
+
This is the repository for the **OWASP Top 10 for Large Language Model Applications**. However, this project has now grown into the comprehensive **OWASP GenAI Security Project** - a global initiative that encompasses multiple security initiatives beyond just the Top 10 list.
13
13
14
-
## 📢 The 2025 List is Available:
15
-
Download OWASP Top 10 for LLM Applications List for 2025 [Full Version](https://genai.owasp.org/resource/owasp-top-10-for-llm-applications-2025/).
14
+
## OWASP GenAI Security Project
16
15
17
-
## Download Additional Resources from our [Website](https://genai.owasp.org) including:
18
-
-[Security & Governance Checklist v1.0](https://genai.owasp.org/resource/llm-applications-cybersecurity-and-governance-checklist-english/) Essential guidance for CISOs managing the rollout of Gen AI technology.
19
-
-[Guide for Preparing and Responding to DeepFakes](https://genai.owasp.org/resource/guide-for-preparing-and-responding-to-deepfake-events/)
20
-
-[2025 AI Security Solutions Directory and Guide](https://genai.owasp.org/ai-security-solutions-landscape/)
16
+
The OWASP GenAI Security Project is a global, open-source initiative dedicated to identifying, mitigating, and documenting security and safety risks associated with generative AI technologies, including large language models (LLMs), agentic AI systems, and AI-driven applications. Our mission is to empower organizations, security professionals, AI practitioners, and policymakers with comprehensive, actionable guidance and tools to ensure the secure development, deployment, and governance of generative AI systems.
21
17
22
-
## Localized versions are also available.
23
-
- Security & Governance Checklist v1.0 - also now [available in French](llm-top-10-governance-doc/LLM_AI_Security_and_Governance_Checklist-v1_FR.pdf) and [Japanese](llm-top-10-governance-doc/LLM_AI_Security_and_Governance_Checklist-v1_1_JP.pdf)
18
+
**Learn more about our mission and charter:**[Project Mission and Charter](https://genai.owasp.org/project-mission-and-charter/)
24
19
25
-
## Want to Contribute your Expertise? Join us.
26
-
- We have a working group channel on the [OWASP Slack](https://owasp.org/slack/invite), so please sign up and then join us on the #project-top10-for-llm channel.
27
-
- The working group is collaborating on our [wiki](https://github.com/OWASP/www-project-top-10-for-large-language-model-applications/wiki)
28
-
- Want to stay updated on periodic progress? [Subscribe to our newsletter](https://llmtop10.beehiiv.com/subscribe) or [Follow our project LinkedIn page](https://www.linkedin.com/company/owasp-top-10-for-large-language-model-applications/)
20
+
**Visit our main project site:**[genai.owasp.org](https://genai.owasp.org)
29
21
30
-
## Just Want to Learn About LLM Security
31
-
New to LLM Application security? Check out our [resources page](https://github.com/OWASP/www-project-top-10-for-large-language-model-applications/wiki/Educational-Resources) to learn more.
22
+
## Latest Top 10 for LLM Applications
23
+
24
+
The OWASP Top 10 for Large Language Model Applications continues to be a core component of our work, identifying the most critical security vulnerabilities in LLM applications.
25
+
26
+
**Access the latest Top 10 for LLM:**[https://genai.owasp.org/llm-top-10/](https://genai.owasp.org/llm-top-10/)
27
+
28
+
## Project Background and Growth
29
+
30
+
The project has evolved significantly since its inception. From a small group of security professionals addressing an urgent security gap in 2023, it has grown into a global community with over 600 contributing experts from more than 18 countries and nearly 8,000 active community members.
31
+
32
+
**Read our full project background:**[Introduction and Background](https://genai.owasp.org/introduction-genai-security-project/)
33
+
34
+
## Get Involved
35
+
36
+
### Contribute to the Project
37
+
We welcome all expert ideas, contributions, suggestions, and remarks from security professionals, researchers, developers, and anyone passionate about AI security.
32
38
33
-
## Become a Project Supporter or Sponsor Sponsorship
34
-
We are a not for profit open source community driven project. If you are interested in supporting the project with reasources or become a sponsor to help us ensure we can continue to sustain the community efforts, offsetting operational, and outreach costs. Visit the [Sponsor Section](https://genai.owasp.org/sponsorship) on our website.
39
+
**Learn how to contribute:**[https://genai.owasp.org/contribute/](https://genai.owasp.org/contribute/)
35
40
36
-
## Thank you to our Current [Sponsors and Supporters](https://genai.owasp.org/supporters/)
41
+
### Join Our Meetings
42
+
Participate in our bi-weekly sync meetings and stay connected with the community.
-[Subscribe to our newsletter](https://llmtop10.beehiiv.com/subscribe) for periodic updates
50
+
51
+
## Project Support
52
+
53
+
We are a not-for-profit, open-source, community-driven project. If you are interested in supporting the project with resources or becoming a sponsor to help us sustain community efforts and offset operational and outreach costs, visit the [Sponsor Section](https://genai.owasp.org/sponsorship) on our website.
54
+
55
+
**Thank you to our current [Sponsors and Supporters](https://genai.owasp.org/supporters/)**
56
+
57
+
## Educational Resources
58
+
59
+
New to LLM Application security? Check out our [resources page](https://github.com/OWASP/www-project-top-10-for-large-language-model-applications/wiki/Educational-Resources) to learn more.
0 commit comments