Skip to content

Commit e9e9355

Browse files
Update project structure to reflect OWASP GenAI Security Project integration (#683)
- Update README.md to reflect project as subproject of OWASP GenAI Security Project - Update CONTRIBUTING.md to direct to centralized contribution guidelines - Update index.md with new mission statement and project evolution - Update project status badge from Lab to Flagship Status - Remove outdated wiki references and direct to main project site - Add Sandy Dunn to leaders.md - Remove Autumn Moulder from CoreTeam.md - Update changes.md with version 2.0.0 entry This update aligns the repository with the broader OWASP GenAI Security Project structure and provides clear direction to the main project site at genai.owasp.org
1 parent d362ca5 commit e9e9355

File tree

6 files changed

+88
-28
lines changed

6 files changed

+88
-28
lines changed

CONTRIBUTING.md

Lines changed: 17 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,9 +1,24 @@
11
# Contributing Guidelines
22

3-
Thank you for your interest in contributing to an OWASP project. We welcome all contributions and appreciate your efforts to improve our projects.
3+
Thank you for your interest in contributing to the OWASP Top 10 for Large Language Model Applications! We are a community-driven project and welcome all contributors, regardless of their background or experience level.
4+
5+
## Community-Driven Project
6+
7+
The OWASP Top 10 for LLM Applications is an open source effort that thrives on community collaboration. We welcome all expert ideas, contributions, suggestions, and remarks from security professionals, researchers, developers, and anyone passionate about AI security.
48

59
## Getting Started
610

7-
We are managing contributions to the OWASP Top 10 for Large Language Model Applications through the wiki feature of our GitHub repository. You can find full directions on how to get involved [here](https://github.com/OWASP/www-project-top-10-for-large-language-model-applications/wiki).
11+
For comprehensive contributor guidelines, including information about our various projects and initiatives, please visit our main project site: **[https://genai.owasp.org/contribute/](https://genai.owasp.org/contribute/)**
12+
13+
## Style Guidelines
814

915
Please make sure to consult the [Style Guide](./documentation/style/README.md) to ensure consistent styling with your contributions.
16+
17+
## Join Our Community
18+
19+
- Join our bi-weekly sync meetings
20+
- Participate in our Slack channels for discussions
21+
- Contribute to translations, publishing, data gathering, and more
22+
- No OWASP membership required to contribute!
23+
24+
For more details on how to get involved, visit our [contribute page](https://genai.owasp.org/contribute/).

CoreTeam.md

Lines changed: 0 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1,4 +1,3 @@
1-
21
# Core Team Members for version 1.0
32

43
This version is now legacy. [New version here](https://genai.owasp.org/contributors/) is maintained on the site.
@@ -9,7 +8,6 @@ These individuals played especially key roles in the creation of the version 1.0
98
| ------------------ | -------------- | --------------------- | ----------------------------------------------------------------------------------- |
109
| Steve Wilson | Overall Lead | [Contrast Security](https://www.contrastsecurity.com/) | [LinkedIn](https://www.linkedin.com/in/wilsonsd/), [Twitter](https://twitter.com/virtualsteve), [GitHub](https://github.com/virtualsteve-star), [Book](https://www.contrastsecurity.com/hubfs/Cybersecurity%20and%20Artificial%20Intelligence%20Threats%20and%20Opportunities.pdf) |
1110
| Mike Finch | Design Lead | [HackerOne](https://www.hackerone.com) | [LinkedIn](https://www.linkedin.com/in/mkfnch), [Twitter](https://twitter.com/mkfnch), [Personal](https://mkfnch.com) |
12-
| Autumn Moulder | PR Lead | | |
1311
| Ads Dawson | Expert | [Dreadnode](https://dreadnode.op) | [LinkedIn](https://www.linkedin.com/in/adamdawson0/), [GitHub](https://github.com/GangGreenTemperTatum) |
1412
| Andy Smith | Expert | | [LinkedIn](https://www.linkedin.com/in/andysmith-uk/), [Twitter](https://twitter.com/rot169), [Bio](https://www.sans.org/profiles/andy-smith/)|
1513
| David Rowe | Expert | [AWS](http://aws.amazon.com) | [LinkedIn](https://www.linkedin.com/in/davidprowe/), [Twitter](https://twitter.com/davidprowe/), [GitHub](https://github.com/davidprowe) |

README.md

Lines changed: 11 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -6,12 +6,18 @@ OWASP Foundation Web Repository
66
# OWASP Top 10 for Large Language Model Applications
77

88
[![Current version in-flight](https://img.shields.io/badge/current_version-v2.0-purple)](https://www.linkedin.com/posts/wilsonsd_announcing-the-version-2-project-its-time-activity-7157734167244378113-s2v2?utm_source=share&utm_medium=member_ios)
9-
[![OWASP Lab Status project](https://img.shields.io/badge/owasp-labstatus-blue.svg)](https://owasp.org/projects/)
9+
[![OWASP Flagship Status project](https://img.shields.io/badge/owasp-flagship-blue.svg)](https://owasp.org/projects/)
1010
[![License: CC BY-SA 4.0](https://img.shields.io/badge/License-CC%20BY--SA%204.0-lightgrey.svg)](https://creativecommons.org/licenses/by-sa/4.0/)
1111
[![genai.owasp.org](https://img.shields.io/badge/officialsite-genai.owasp.org-032CFA.svg)](https://genai.owasp.org)
1212

1313
Welcome to the official repository for the OWASP Top 10 for Large Language Model Applications!
1414

15+
## About This Repository
16+
17+
This repository contains the OWASP Top 10 for Large Language Model Applications, which is now housed under the comprehensive **OWASP GenAI Security Project**. The OWASP GenAI Security Project is a global, open-source initiative dedicated to identifying, mitigating, and documenting security and safety risks associated with generative AI technologies.
18+
19+
**Visit our main project site:** [genai.owasp.org](https://genai.owasp.org)
20+
1521
## Overview and Audience 🗣️
1622

1723
The OWASP Top 10 for Large Language Model Applications is a standard awareness document for developers and web application security. It represents a broad consensus about the most critical security risks to Large Language Model (LLM) applications. There are other ongoing frameworks both inside and outside of OWASP that are not to be confused with this project and is currently scoped towards only LLM Application Security.
@@ -24,17 +30,17 @@ The primary aim of this project is to provide a comprehensible and adoptable gui
2430

2531
## Mission Statement 🚀
2632

27-
Our mission is to make application security visible, so that people and organizations can make informed decisions about application security risks related to LLMs. While our list shares DNA with vulnerability types found in other OWASP Top 10 lists, we do not simply reiterate these vulnerabilities. Instead, we delve into these vulnerabilities unique implications when encountered in applications utilizing LLMs.
33+
Our mission is to make application security visible, so that people and organizations can make informed decisions about application security risks related to LLMs. While our list shares DNA with vulnerability types found in other OWASP Top 10 lists, we do not simply reiterate these vulnerabilities. Instead, we delve into these vulnerabilities' unique implications when encountered in applications utilizing LLMs.
2834

29-
Our goal is to bridge the divide between general application security principles and the specific challenges posed by LLMs. The groups goals include exploring how conventional vulnerabilities may pose different risks or be exploited in novel ways within LLMs and how developers must adapt traditional remediation strategies for applications utilizing LLMs.
35+
Our goal is to bridge the divide between general application security principles and the specific challenges posed by LLMs. The group's goals include exploring how conventional vulnerabilities may pose different risks or be exploited in novel ways within LLMs and how developers must adapt traditional remediation strategies for applications utilizing LLMs.
3036

3137
## Contribution 👋
3238

33-
The first version of this list was contributed by Steve Wilson of Contrast Security. We encourage the community to contribute and help improve the project. If you have any suggestions, feedback or want to help improve the list, feel free to open an issue or send a pull request.
39+
The first version of this list was contributed by Steve Wilson of Contrast Security. We encourage the community to contribute and help improve the project. If you have any suggestions, feedback or want to help improve the list, feel free to open an issue or send a pull request.
3440

3541
We have a working group channel on the [OWASP Slack](https://owasp.org/slack/invite), so please sign up and then join us on the #project-top10-llm channel.
3642

37-
Please hop over to [our wiki page](https://github.com/OWASP/www-project-top-10-for-large-language-model-applications/wiki) to collaborate on the project and stay up to date with the latest meetings and current roadmap.
43+
**Learn how to contribute:** [https://genai.owasp.org/contribute/](https://genai.owasp.org/contribute/)
3844

3945
## License
4046

changes.md

Lines changed: 17 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,23 @@ All notable changes to the OWASP Top 10 for LLM Applications project will be doc
44

55
The format is based on [Keep a Changelog](https://keepachangelog.com/en/1.0.0/), and this project adheres to [Semantic Versioning](https://semver.org/spec/v2.0.0.html).
66

7+
## [2.0.0] - 2025-01-27
8+
9+
### Changed
10+
11+
- Updated project documentation to reflect the OWASP Top 10 for Large Language Model Applications as a subproject of the comprehensive OWASP GenAI Security Project
12+
- Updated README.md to include reference to the main project site at genai.owasp.org
13+
- Updated CONTRIBUTING.md to direct contributors to the centralized contribution guidelines
14+
- Updated index.md to reflect the project's evolution and growth into the OWASP GenAI Security Project
15+
- Updated project status badge from "Lab Status" to "Flagship Status" in README.md
16+
- Removed outdated wiki references and directed users to the main project site for comprehensive information
17+
18+
### Added
19+
20+
- Links to the main OWASP GenAI Security Project website and various initiative pages
21+
- Updated mission statement reflecting the broader scope of the GenAI Security Project
22+
- References to the project's growth to over 600 contributing experts from more than 18 countries
23+
724
## [1.0.1] - 2023-08-26
825

926
[v1.1 Instructions for the Expert Group reference](https://github.com/OWASP/www-project-top-10-for-large-language-model-applications/wiki/v1_1-phases#v11-instructions-for-the-expert-group)

index.md

Lines changed: 42 additions & 19 deletions
Original file line numberDiff line numberDiff line change
@@ -7,31 +7,54 @@ tags: example-tag
77
pitch: Aims to educate developers, designers, architects, managers, and organizations about the potential security risks when deploying and managing Large Language Models (LLMs)
88
---
99

10-
The OWASP Top 10 for Large Language Model Applications Project aims to educate developers, designers, architects, managers, and organizations about the potential security risks when deploying and managing Large Language Models (LLMs) and Generative AI applications. The project provides a range of resources. Most notably the OWASP Top 10 list for LLM applications listing the top 10 most critical vulnerabilities often seen in LLM applications, highlighting their potential impact, ease of exploitation, and prevalence in real-world applications.
10+
## About This Repository
1111

12-
Examples of vulnerabilities include prompt injections, data leakage, inadequate sandboxing, and unauthorized code execution, among others. The goal is to raise awareness of these vulnerabilities, suggest remediation strategies, and ultimately improve the security posture of LLM applications.
12+
This is the repository for the **OWASP Top 10 for Large Language Model Applications**. However, this project has now grown into the comprehensive **OWASP GenAI Security Project** - a global initiative that encompasses multiple security initiatives beyond just the Top 10 list.
1313

14-
## 📢 The 2025 List is Available:
15-
Download OWASP Top 10 for LLM Applications List for 2025 [Full Version](https://genai.owasp.org/resource/owasp-top-10-for-llm-applications-2025/).
14+
## OWASP GenAI Security Project
1615

17-
## Download Additional Resources from our [Website](https://genai.owasp.org) including:
18-
- [Security & Governance Checklist v1.0](https://genai.owasp.org/resource/llm-applications-cybersecurity-and-governance-checklist-english/) Essential guidance for CISOs managing the rollout of Gen AI technology.
19-
- [Guide for Preparing and Responding to DeepFakes](https://genai.owasp.org/resource/guide-for-preparing-and-responding-to-deepfake-events/)
20-
- [2025 AI Security Solutions Directory and Guide](https://genai.owasp.org/ai-security-solutions-landscape/)
16+
The OWASP GenAI Security Project is a global, open-source initiative dedicated to identifying, mitigating, and documenting security and safety risks associated with generative AI technologies, including large language models (LLMs), agentic AI systems, and AI-driven applications. Our mission is to empower organizations, security professionals, AI practitioners, and policymakers with comprehensive, actionable guidance and tools to ensure the secure development, deployment, and governance of generative AI systems.
2117

22-
## Localized versions are also available.
23-
- Security & Governance Checklist v1.0 - also now [available in French](llm-top-10-governance-doc/LLM_AI_Security_and_Governance_Checklist-v1_FR.pdf) and [Japanese](llm-top-10-governance-doc/LLM_AI_Security_and_Governance_Checklist-v1_1_JP.pdf)
18+
**Learn more about our mission and charter:** [Project Mission and Charter](https://genai.owasp.org/project-mission-and-charter/)
2419

25-
## Want to Contribute your Expertise? Join us.
26-
- We have a working group channel on the [OWASP Slack](https://owasp.org/slack/invite), so please sign up and then join us on the #project-top10-for-llm channel.
27-
- The working group is collaborating on our [wiki](https://github.com/OWASP/www-project-top-10-for-large-language-model-applications/wiki)
28-
- Want to stay updated on periodic progress? [Subscribe to our newsletter](https://llmtop10.beehiiv.com/subscribe) or [Follow our project LinkedIn page](https://www.linkedin.com/company/owasp-top-10-for-large-language-model-applications/)
20+
**Visit our main project site:** [genai.owasp.org](https://genai.owasp.org)
2921

30-
## Just Want to Learn About LLM Security
31-
New to LLM Application security? Check out our [resources page](https://github.com/OWASP/www-project-top-10-for-large-language-model-applications/wiki/Educational-Resources) to learn more.
22+
## Latest Top 10 for LLM Applications
23+
24+
The OWASP Top 10 for Large Language Model Applications continues to be a core component of our work, identifying the most critical security vulnerabilities in LLM applications.
25+
26+
**Access the latest Top 10 for LLM:** [https://genai.owasp.org/llm-top-10/](https://genai.owasp.org/llm-top-10/)
27+
28+
## Project Background and Growth
29+
30+
The project has evolved significantly since its inception. From a small group of security professionals addressing an urgent security gap in 2023, it has grown into a global community with over 600 contributing experts from more than 18 countries and nearly 8,000 active community members.
31+
32+
**Read our full project background:** [Introduction and Background](https://genai.owasp.org/introduction-genai-security-project/)
33+
34+
## Get Involved
35+
36+
### Contribute to the Project
37+
We welcome all expert ideas, contributions, suggestions, and remarks from security professionals, researchers, developers, and anyone passionate about AI security.
3238

33-
## Become a Project Supporter or Sponsor Sponsorship
34-
We are a not for profit open source community driven project. If you are interested in supporting the project with reasources or become a sponsor to help us ensure we can continue to sustain the community efforts, offsetting operational, and outreach costs. Visit the [Sponsor Section](https://genai.owasp.org/sponsorship) on our website.
39+
**Learn how to contribute:** [https://genai.owasp.org/contribute/](https://genai.owasp.org/contribute/)
3540

36-
## Thank you to our Current [Sponsors and Supporters](https://genai.owasp.org/supporters/)
41+
### Join Our Meetings
42+
Participate in our bi-weekly sync meetings and stay connected with the community.
43+
44+
**Meeting information:** [https://genai.owasp.org/meetings/](https://genai.owasp.org/meetings/)
45+
46+
### Connect with the Community
47+
- Join our working group channel on the [OWASP Slack](https://owasp.org/slack/invite) - sign up and join us on the `#project-top10-for-llm` channel
48+
- [Follow our project LinkedIn page](https://www.linkedin.com/company/owasp-top-10-for-large-language-model-applications/)
49+
- [Subscribe to our newsletter](https://llmtop10.beehiiv.com/subscribe) for periodic updates
50+
51+
## Project Support
52+
53+
We are a not-for-profit, open-source, community-driven project. If you are interested in supporting the project with resources or becoming a sponsor to help us sustain community efforts and offset operational and outreach costs, visit the [Sponsor Section](https://genai.owasp.org/sponsorship) on our website.
54+
55+
**Thank you to our current [Sponsors and Supporters](https://genai.owasp.org/supporters/)**
56+
57+
## Educational Resources
58+
59+
New to LLM Application security? Check out our [resources page](https://github.com/OWASP/www-project-top-10-for-large-language-model-applications/wiki/Educational-Resources) to learn more.
3760

leaders.md

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -4,6 +4,7 @@
44
- Co-lead [Ads Dawson](mailto:[email protected]) - [LinkedIn](https://www.linkedin.com/in/adamdawson0/) [GitHub](https://github.com/GangGreenTemperTatum)
55
- Co-lead [John Sotiropoulos](mailto:[email protected]) - [LinkedIn](https://www.linkedin.com/in/jsotiropoulos/)
66
- Co-lead [Scott Clinton](mailto:[email protected]) - [LinkedIn](https://www.linkedin.com/in/scottjclinton/)
7+
- Co-lead [Sandy Dunn](mailto:[email protected]) - [LinkedIn](https://www.linkedin.com/in/sandydunnciso/)
78

89
### Core Leadership vTeam
910

0 commit comments

Comments
 (0)