OWASP LLM Top 10 coverage
This view presents the current product catalogue: 32 probes across all ten categories (17 locked-base + 15 expansion; commit 8752ede). Per-tenant states come only from conclusive, persisted evidence. The separate v0.5.3 locked-corpus calibration is historical methodology context, not a measure of the current engine.
Key points
- The current product corpus includes 32 probes across all ten OWASP LLM categories, LLM01 through LLM10 (corpus expansion commit 8752ede).
- Per-tenant states and aggregate coverage appear only when completed-run evidence is conclusive and its persisted lineage can be reproduced.
- The archived methodology reference covers a locked 17-probe corpus across 5 of 10 categories; it does not measure today's engine or a tenant's defenses.
- Its ten executions per scenario (40 total; metrics record 95ac0462) repeated that same corpus rather than sampling independently; current accuracy is N/A.
- The separate mutation record (57f15b67) contains 17 originals and 85 variants across four synthetic lattice targets. No historical rate is carried into the current product.
01
Archived locked-corpus scope (v0.5.3 · 17 probes · 5/10)
- LLM01 (prompt injection) — included in the locked historical reference; current-engine performance in this reference: N/A.
- LLM02 (sensitive information disclosure) — included in the locked historical reference; current-engine performance in this reference: N/A.
- LLM06 (excessive agency) — included in the locked historical reference; current-engine performance in this reference: N/A.
- LLM07 (system prompt leakage) — included in the locked historical reference; current-engine performance in this reference: N/A.
- LLM10 (unbounded consumption) — included in the locked historical reference; current-engine performance in this reference: N/A.
02
Per-tenant state machine
- open — at least one open finding from decision-grade evidence is tagged with the category.
- remediated — decision-grade evidence shows prior findings and all are closed.
- tested — conclusive evidence tested the category without an open finding.
- untested — the category is in the current catalogue, but no conclusive evidence has tested it.
03
What this view is NOT
- The historical 5/10 reference is not an accuracy estimate for the current engine or a tenant.
- Ten repeated executions of one locked corpus do not support an independent-sample confidence interval or wider extrapolation.
- Current coverage is evidence within the tested corpus, not an audit, certification, or guarantee against attacks in the wild.