Framework Explorer

OWASP LLM Top 10

Reviewed AuditaAI assessments connect documented offering behavior to OWASP risks. These are not vendor certifications or OWASP endorsements.

Official OWASP source

LLM01:2025

Prompt Injection

User prompts or external content alter an LLM application's intended behavior.

30 reviewed alignments
Reviewed offering assessments+
Zero Day Investigative Network · 0DIN AI Security ScannerInferred alignmenthigh confidence · 2 sources

0DIN AI Security Scanner evaluates LLM and GenAI application behavior against exploit and jailbreak test suites.

AuditaAI assessment: scanner exploit testing that includes jailbreak and prompt-manipulation scenarios aligns with prompt-injection risk evaluation.

Cranium AI, Inc. · Cranium AI Security and Governance PlatformInferred alignmentmedium confidence · 2 sources

Cranium AI platform interaction inspection is positioned to detect adversarial prompt-injection patterns in runtime workflows.

Prompt-injection pattern inspection aligns with OWASP prompt-injection risk context.

Anthropic · Constitutional ClassifiersInferred alignmenthigh confidence · 1 source

Anthropic applies constitutional classifier safeguards to detect and block jailbreak attempts against Claude model behavior.

AuditaAI assessment: classifier defenses against jailbreak attempts address prompt-injection risk.

Amazon Web Services · Amazon Bedrock GuardrailsInferred alignmenthigh confidence · 1 source

Amazon Bedrock Guardrails applies inline controls that can block prompt-injection and jailbreak-style requests before model outputs are returned.

Blocking prompt-injection and jailbreak requests aligns with OWASP prompt-injection risk mitigation context.

F5, Inc. · F5 AI GuardrailsInferred alignmenthigh confidence · 1 source

F5 AI Guardrails applies inline policy controls that can block prompt-injection payloads before requests reach downstream models and tools.

Blocking prompt-injection payloads aligns with OWASP prompt-injection mitigation context.

Cato Networks · Cato AI Security (AISEC)Inferred alignmenthigh confidence · 1 source

Cato AI Security runtime monitoring detects prompt-injection patterns and policy-violating AI prompt activity.

Detection of prompt-injection patterns aligns with OWASP prompt-injection risk context.

Check Point Software Technologies · AI Agent SecurityInferred alignmenthigh confidence · 1 source

AI Agent Security helps detect prompt attacks, indirect injection, and sensitive data exposure across agent prompts, responses, and tool use.

Detection of prompt and indirect injection behavior aligns with prompt-injection risk mitigation context.

Cisco · AI Runtime ProtectionInferred alignmenthigh confidence · 1 source

AI Runtime Protection provides runtime guardrails for prompt and response threat mitigation.

Runtime guardrails for prompt threat mitigation align to prompt-injection risk context.

Dynamo AI · DynamoGuardDirect alignmenthigh confidence · 1 source

DynamoGuard performs low-latency runtime inspection of prompts and model completions to detect and block prompt injection, jailbreaks, PII leakage, and toxic content.

DynamoGuard explicitly prevents prompt injection and jailbreak payloads at runtime.

Enkrypt AI · SiftDirect alignmenthigh confidence · 1 source

Sift intercepts API traffic to foundation models to detect and block prompt injection, jailbreaking, PII leakage, and toxic outputs at the gateway boundary.

Sift explicitly prevents prompt injection and jailbreaking attempts in API traffic.

Gray Swan AI · CygnalInferred alignmenthigh confidence · 1 source

Cygnal classifies and blocks adversarial AI inputs and unsafe outputs during production runtime.

AuditaAI assessment: runtime blocking of adversarial input aligns with prompt-injection risk mitigation.

Google Cloud · Model ArmorInferred alignmenthigh confidence · 1 source

Model Armor scans prompts and responses for prompt injection and jailbreak content and can return a block verdict when a violation is detected.

AuditaAI assessment: prompt and jailbreak inspection with a block verdict addresses the documented prompt-injection risk.

Glow · Glow AI-Powered Endpoint Security PlatformInferred alignmentmedium confidence · 1 source

Glow continuous endpoint monitoring can detect suspicious AI interaction patterns and prompt-driven misuse across local applications and browser activity.

Detection of prompt-driven misuse patterns aligns with OWASP prompt-injection risk context.

Lasso Security · Runtime Enforcement and AI Detection and ResponseInferred alignmenthigh confidence · 2 sources

Lasso runtime enforcement can block prompt-injection attempts and prevent unsafe autonomous agent actions or unauthorized tool invocation.

Inline blocking of prompt-injection attempts aligns with OWASP prompt-injection mitigation context.

Meta Platforms, Inc. · Llama Prompt GuardInferred alignmenthigh confidence · 1 source

Llama Prompt Guard classifies input text for prompt injection and jailbreak patterns before the text reaches the primary model.

AuditaAI assessment: detection of injected and jailbreak prompts addresses prompt-injection risk.

Mindgard · AI Runtime Threat Detection and ResponseInferred alignmenthigh confidence · 1 source

Runtime guardrails are applied to block prompt injection attack paths before harmful model behavior propagates.

Blocking prompt-injection attack paths aligns with OWASP prompt-injection mitigation context.

Microsoft · Azure AI Content Safety and Prompt ShieldsInferred alignmenthigh confidence · 1 source

Azure AI Content Safety and Prompt Shields identify direct and indirect prompt injection and related unsafe prompt patterns before they reach downstream model behavior.

The source explicitly addresses direct and indirect prompt injection defense behavior.

Nightfall AI · AI Agent SecurityInferred alignmentmedium confidence · 1 source

AI Agent Security uses hook-level interception and tool-call governance to constrain unsafe autonomous actions before execution.

Interception of prompt-driven tool-action chains can mitigate prompt-injection-induced execution abuse.

NVIDIA Corporation · garakInferred alignmenthigh confidence · 1 source

garak probes language-model endpoints across attack classes including jailbreaks, prompt injection, and data leakage to identify model security weaknesses.

AuditaAI assessment: probing for prompt injection and jailbreak weaknesses evaluates exposure to prompt-injection risk.

Alice · WonderFenceInferred alignmenthigh confidence · 1 source

WonderFence intercepts unsafe model inputs and blocks harmful outputs in production LLM and agentic workflows.

AuditaAI assessment: runtime blocking of unsafe input patterns aligns with prompt-injection risk reduction.

Palo Alto Networks · Prisma AIRSInferred alignmentmedium confidence · 1 source

Prisma AIRS applies real-time safeguards to AI prompts, responses, model interactions, agent actions, and data exposure paths.

AuditaAI assessment: real-time safeguards for prompts and model interactions address prompt-injection risk.

Protect AI · LLM GuardInferred alignmenthigh confidence · 1 source

LLM Guard inspects, sanitizes, and evaluates LLM prompts and model completions against prompt injection, jailbreaks, and sensitive data leakage.

AuditaAI assessment: LLM Guard detects and sanitizes prompt injection attempts and jailbreaks before LLM processing.

Promptfoo · Promptfoo CoreDirect alignmenthigh confidence · 1 source

Promptfoo executes automated adversarial test fixtures and benchmark assertions against LLM endpoints to evaluate resistance to prompt injection, toxicity, and system prompt extraction.

Promptfoo documentation explicitly provides dedicated red teaming test suites for prompt injection and jailbreaking.

Prompt Security · Prompt SecurityInferred alignmenthigh confidence · 1 source

Prompt Security runtime enforcement can block prompt-injection attempts in employee and application AI interaction paths.

Runtime blocking of prompt-injection attempts aligns with OWASP prompt-injection risk mitigation context.

Snowflake Inc. · Cortex AI GuardrailsInferred alignmenthigh confidence · 1 source

Cortex AI Guardrails evaluate runtime prompts and responses to mitigate direct and indirect prompt-injection and jailbreak attempts.

Documented runtime guardrails for direct and indirect prompt injection align with OWASP LLM01 context.

TrendAI · TrendAI Vision One AI SecurityInferred alignmenthigh confidence · 2 sources

TrendAI Vision One AI Security inspects and controls enterprise traffic to public and private GenAI services to reduce prompt-injection abuse and unauthorized AI use.

AuditaAI assessment: runtime controls that inspect and restrict unsafe GenAI traffic align to prompt-injection risk reduction.

Verno Labs · Verno Labs AI Agent Security PlatformInferred alignmentmedium confidence · 1 source

Verno Labs performs automated adversarial testing to evaluate AI agent security weaknesses before production impact.

AuditaAI assessment: adversarial testing of agent and LLM behavior contributes prompt-injection risk evaluation.

Votal AI · Votal Runtime Security PlatformInferred alignmenthigh confidence · 2 sources

Votal blocks prompt-injection patterns and PII policy violations through layered runtime guardrail controls.

AuditaAI assessment: prompt-injection blocking controls align with LLM prompt-injection risk reduction.

Zenity · Runtime Boundaries and AIDRInferred alignmentmedium confidence · 2 sources

Zenity runtime boundaries can block unsafe agent actions, including risky tool usage and unauthorized task execution.

Runtime prevention of harmful agent decisions can mitigate prompt-driven abuse effects in execution paths.

SPLX · SPLX Runtime GuardrailsInferred alignmenthigh confidence · 1 source

Zscaler AI Security runtime protection blocks prompt injection, data poisoning, and malicious URLs in AI interactions.

AuditaAI assessment: runtime blocking of documented prompt injection addresses the prompt-injection risk.

LLM02:2025

Sensitive Information Disclosure

Sensitive information is exposed through an LLM application or its interactions.

12 reviewed alignments
Reviewed offering assessments+
Dynamo AI · DynamoGuardDirect alignmenthigh confidence · 1 source

DynamoGuard performs low-latency runtime inspection of prompts and model completions to detect and block prompt injection, jailbreaks, PII leakage, and toxic content.

DynamoGuard explicitly detects and filters sensitive information and PII to prevent disclosure.

Enkrypt AI · SiftDirect alignmenthigh confidence · 1 source

Sift intercepts API traffic to foundation models to detect and block prompt injection, jailbreaking, PII leakage, and toxic outputs at the gateway boundary.

Sift explicitly detects and prevents sensitive data leakage in model traffic.

Google Cloud · Model ArmorInferred alignmenthigh confidence · 1 source

Model Armor can inspect, transform, tokenize, and redact sensitive elements in AI prompts and responses through Sensitive Data Protection integration.

AuditaAI assessment: inspecting, tokenizing, and redacting sensitive prompt and response content addresses sensitive-information disclosure risk.

Harmonic Security · Harmonic Security PlatformDirect alignmenthigh confidence · 1 source

Harmonic Security inspects user prompts in real time to detect sensitive enterprise information (PII, source code, financial data) and enforces redaction or blocking policies prior to transmission to external LLMs.

AuditaAI assessment: prompt data inspection and redaction directly mitigate sensitive information disclosure to external AI services.

HiddenLayer · AI Runtime SecurityInferred alignmentmedium confidence · 1 source

AI Runtime Security can detect, block, or redact unsafe actions and sensitive information according to policy and platform capabilities.

Blocking or redacting sensitive information at runtime is aligned to sensitive-information disclosure context.

Mirror Security · Mirror Security SuiteInferred alignmenthigh confidence · 1 source

Mirror Security keeps prompts, context, and responses encrypted through inference workflows while enforcing decision-time policies.

AuditaAI assessment: protecting prompt and context data in-use reduces sensitive-information disclosure risk.

Palo Alto Networks · Prisma AIRSInferred alignmentmedium confidence · 1 source

Prisma AIRS applies real-time safeguards to AI prompts, responses, model interactions, agent actions, and data exposure paths.

AuditaAI assessment: runtime safeguards across data-exposure paths address sensitive-information disclosure risk.

Portkey · PortkeyInferred alignmenthigh confidence · 1 source

Portkey automatically redacts sensitive data from requests before sending them to an LLM.

AuditaAI assessment: redacting sensitive data before an LLM request addresses sensitive-information disclosure risk.

Protect AI · LLM GuardInferred alignmenthigh confidence · 1 source

LLM Guard inspects, sanitizes, and evaluates LLM prompts and model completions against prompt injection, jailbreaks, and sensitive data leakage.

AuditaAI assessment: LLM Guard scans prompts and model outputs for sensitive data and PII to prevent sensitive information disclosure.

Promptfoo · Promptfoo CoreDirect alignmenthigh confidence · 1 source

Promptfoo executes automated adversarial test fixtures and benchmark assertions against LLM endpoints to evaluate resistance to prompt injection, toxicity, and system prompt extraction.

Promptfoo documentation explicitly provides automated test suites probing for sensitive data and PII disclosure.

TrendAI · TrendAI Vision One AI SecurityInferred alignmenthigh confidence · 1 source

TrendAI combines AI Scanner pre-deployment testing with AI Guard runtime controls to detect vulnerabilities and reduce sensitive data leakage in AI applications.

AuditaAI assessment: controls to reduce sensitive data leakage from AI applications align to sensitive-information disclosure risk.

Zscaler · Zscaler Data SecurityInferred alignmenthigh confidence · 1 source

Zscaler Data Security inspects AI usage and prompts and can block risky access or enforce prompt DLP to prevent data loss.

AuditaAI assessment: prompt DLP and access blocking address sensitive information disclosure through AI usage.

LLM03:2025

Supply Chain

LLM supply-chain components introduce vulnerabilities or compromise risk.

7 reviewed alignments
Reviewed offering assessments+
Chainguard · Chainguard Secure AI SDLCInferred alignmenthigh confidence · 1 source

Chainguard AI Security documents software supply chain coverage across SDLC phases, including trusted dependencies, CI/CD integrity, and hardened runtime foundations.

Securing dependencies and CI/CD integrity across AI SDLC phases aligns with software supply-chain risk mitigation.

Chainguard · Chainguard ContainersInferred alignmentmedium confidence · 1 source

Chainguard Containers is positioned as a built-from-source container catalog designed to minimize known vulnerabilities in development and production pipelines.

Built-from-source container artifacts positioned to reduce vulnerability exposure align to supply-chain risk mitigation context.

Wiz · Wiz AI-BOMInferred alignmentmedium confidence · 1 source

Wiz AI-BOM continuously inventories AI models, datasets, frameworks, software dependencies, identities, access paths, and infrastructure.

AuditaAI assessment: a continuously maintained inventory of models, datasets, frameworks, and dependencies supports identifying LLM supply-chain exposure.

HiddenLayer · AI Supply Chain SecurityInferred alignmenthigh confidence · 1 source

AI Supply Chain Security analyzes model architectures, layers, weights, and artifacts for tampering or anomalies and tracks model lineage, origin, and licensing.

Inspecting model artifacts and lineage for tampering aligns to supply-chain risk context.

Palo Alto Networks · Prisma AIRSInferred alignmenthigh confidence · 1 source

Prisma AIRS scans third-party models for tampering, malicious scripts, and deserialization risks.

AuditaAI assessment: scanning third-party models for tampering and malicious artifacts addresses LLM supply-chain risk.

Koi Security · Koi Agentic Endpoint SecurityInferred alignmentmedium confidence · 1 source

Koi AES evaluates code differences and behavioral shifts in real time to identify software supply-chain risk.

AuditaAI assessment: identifying supply-chain shifts in software and AI model environments supports addressing supply-chain risk.

Protect AI · ModelScanInferred alignmenthigh confidence · 1 source

ModelScan statically analyzes serialized ML model files (PyTorch, Pickle, SavedModel, Keras) to detect embedded code execution exploits and malicious payload injections.

AuditaAI assessment: ModelScan inspects model file formats and dependencies to prevent supply chain code execution exploits.

LLM04:2025

Data and Model Poisoning

Training, tuning, retrieval, or other data is corrupted to affect model behavior.

1 reviewed alignment
Reviewed offering assessments+
SPLX · SPLX Runtime GuardrailsInferred alignmentmedium confidence · 1 source

Zscaler AI Security runtime protection blocks prompt injection, data poisoning, and malicious URLs in AI interactions.

AuditaAI assessment: runtime blocking of documented data-poisoning attempts addresses data and model poisoning risk.

LLM05:2025

Improper Output Handling

LLM output is insufficiently validated before downstream use.

1 reviewed alignment
Reviewed offering assessments+
Check Point Software Technologies · Check Point AI Security SolutionsInferred alignmentmedium confidence · 1 source

Check Point AI Security documents runtime enforcement that includes protection against harmful outputs in AI interactions.

Documented runtime protection against harmful outputs aligns with improper-output-handling risk mitigation context.

LLM06:2025

Excessive Agency

An LLM system receives excessive permissions, functionality, or autonomy.

29 reviewed alignments
Reviewed offering assessments+
BeyondTrust Corporation · BeyondTrust AI Agent Security & InsightsInferred alignmenthigh confidence · 1 source

BeyondTrust provides MCP server access controls and Secrets Insights integration to reduce unsafe secret exposure.

MCP access controls and secrets protection reduce excessive agency in agent tool use.

Cranium AI, Inc. · Cranium AI Security and Governance PlatformInferred alignmenthigh confidence · 2 sources

Cranium AI platform is positioned with runtime policy controls to govern unsafe autonomous agent behavior and over-permissioned execution paths.

Controls over unsafe autonomous execution align with OWASP excessive-agency risk mitigation context.

Cranium AI, Inc. · Cranium AI Security and Governance PlatformInferred alignmenthigh confidence · 2 sources

Cranium AI platform data controls are positioned to prevent sensitive information disclosure across model and agent workflows.

Preventing sensitive information disclosure in model and agent workflows aligns with OWASP sensitive-disclosure context.

Tenable Holdings, Inc. · Tenable One AI ExposureInferred alignmentmedium confidence · 2 sources

Tenable One AI Exposure surfaces identity and entitlement risk for AI workloads, including over-permissioned access paths that can increase autonomous abuse risk.

Over-permissioned AI access paths align with excessive-agency risk mitigation context.

Amazon Web Services · Amazon Bedrock GuardrailsInferred alignmenthigh confidence · 1 source

Amazon Bedrock Guardrails includes sensitive-information policy controls to reduce protected-data leakage in prompt and response flows.

Sensitive-information protections in prompt and response channels align with OWASP sensitive-disclosure risk context.

F5, Inc. · F5 AI GuardrailsInferred alignmenthigh confidence · 1 source

F5 AI Guardrails inspects prompts and responses to redact or block sensitive data and reduce leakage to external AI systems.

Prompt and response sensitive-data protections align with OWASP sensitive-disclosure mitigation context.

F5, Inc. · F5 AI GuardrailsInferred alignmentmedium confidence · 2 sources

F5 AI Guardrails applies agent-focused runtime controls to constrain unsafe autonomous actions and high-risk tool execution paths.

Controls over high-risk autonomous execution paths align with OWASP excessive-agency risk mitigation context.

Cato Networks · Cato AI Security (AISEC)Inferred alignmenthigh confidence · 1 source

Cato AI Security applies inline controls to block sensitive data exfiltration to unauthorized AI services and channels.

Blocking sensitive data transfer in AI interactions aligns with OWASP sensitive-disclosure risk mitigation context.

Cato Networks · Cato AI Security (AISEC)Inferred alignmentmedium confidence · 2 sources

Cato AI Security governance controls constrain unsafe autonomous actions and high-risk tool usage for AI agents and applications.

Controls over unsafe autonomous actions and tool usage align with OWASP excessive-agency risk context.

Check Point Software Technologies · AI Agent SecurityInferred alignmenthigh confidence · 1 source

AI Agent Security governs which tools and MCP servers agents can use, and evaluates agent actions in context to help block unsafe or unauthorized behavior at runtime.

Runtime controls over agent actions and tool use align with excessive-agency risk mitigation context.

Dynamo AI · AgentWardenInferred alignmenthigh confidence · 1 source

AgentWarden enforces security and authorization policies at runtime agent action boundaries across prompts, tool calls, tool responses, and final actions to prevent unauthorized execution and goal hijacking.

Restricting tool execution at agent action boundaries prevents excessive agency.

Glow · Glow AI-Powered Endpoint Security PlatformInferred alignmenthigh confidence · 1 source

Glow endpoint controls can prevent sensitive information exposure through AI-enabled tools and unmanaged local workflows.

Preventing sensitive information exposure in AI-enabled workflows aligns with OWASP sensitive-disclosure risk context.

HiddenLayer · Agentic and MCP SecurityInferred alignmentmedium confidence · 1 source

HiddenLayer presents Agentic and MCP Security as a use case for protecting autonomous agents and MCP-based systems from prompt injection, unsafe tool use, and harmful autonomous actions.

Protection from unsafe autonomous actions and tool use aligns to excessive-agency risk context.

Mindgard · AI Runtime Threat Detection and ResponseInferred alignmentmedium confidence · 1 source

Runtime response workflows support containment and remediation for unsafe agent behavior and unauthorized action chains.

Containing unsafe autonomous action chains aligns with excessive-agency risk mitigation context.

Microsoft · Microsoft Purview for AIInferred alignmenthigh confidence · 1 source

Microsoft Purview for AI applies DLP and sensitivity controls to reduce unauthorized sensitive data transfer in AI interactions.

DLP and sensitivity control behavior aligns with sensitive information disclosure risk mitigation context.

NEO · Neo Security PlatformInferred alignmentmedium confidence · 1 source

Neo Security Platform is positioned to prevent agentic threats by controlling unsafe runtime action paths and over-permissioned execution conditions.

Controls over over-permissioned agentic execution align with excessive-agency risk mitigation context.

Okta · Agent GatewayDirect alignmenthigh confidence · 1 source

Okta Agent Gateway intercepts agent-to-tool and agent-to-API calls at runtime without requiring upstream application code changes.

Runtime interception and dynamic token brokering limit excessive agency in downstream tool use.

Ping Identity Corporation · Agent Gateway & Runtime IdentityDirect alignmenthigh confidence · 1 source

Ping Agent Gateway intercepts agent invocations across multi-cloud proxies and MCP servers to evaluate runtime authorization policies dynamically before executing tool calls.

Agent Gateway constrains excessive agency by enforcing runtime authorization before tool execution.

Nightfall AI · AI Application DLPInferred alignmenthigh confidence · 1 source

AI Application DLP applies pre-submission filtering and policy controls to block sensitive prompt, upload, and clipboard data before transfer to AI providers.

Pre-submission blocking of sensitive prompts and uploads aligns with sensitive-information disclosure risk mitigation context.

Palo Alto Networks · Prisma AIRSInferred alignmenthigh confidence · 1 source

Prisma AIRS verifies agent identity and enforces real-time security controls for agent actions.

AuditaAI assessment: verifying agent identity and enforcing controls on agent actions addresses excessive agency risk.

Koi Security · Koi Agentic Endpoint SecurityInferred alignmentmedium confidence · 1 source

Koi AES enforces endpoint guardrails that approve, flag, or block autonomous tools.

AuditaAI assessment: approving, flagging, or blocking autonomous tools supports limiting excessive agent agency.

Idira · Idira Secure AI AgentsInferred alignmenthigh confidence · 1 source

Idira Secure AI Agents acts as a dynamic agent identity broker that grants an agent access only for the duration of a specific task and automatically revokes permissions once the task completes.

AuditaAI assessment: granting access only for a task's duration and revoking it afterward reduces excessive standing agency.

SailPoint generates an AI Bill of Materials that details tools, data access boundaries, model dependencies, and authority limits for each deployed agent.

AI BOM visibility and authority limits support least-privilege control over agent actions.

Saviynt Agent Access Gateway intercepts agent-to-tool and agent-to-application API calls at runtime and evaluates them against task intent before permitting execution.

Task-intent checks and ephemeral credentials constrain excessive agency.

Prompt Security · Prompt SecurityInferred alignmenthigh confidence · 1 source

Prompt Security prompt and content controls redact sensitive enterprise data before it is sent to external models.

Prompt data redaction controls align with OWASP sensitive-disclosure mitigation context.

Prompt Security · Prompt SecurityInferred alignmentmedium confidence · 2 sources

Prompt Security agent-focused governance restricts risky autonomous tool use and unsafe execution decisions.

Agent governance over risky autonomous actions aligns with OWASP excessive-agency mitigation context.

Snowflake Inc. · Cortex AI GatewayInferred alignmenthigh confidence · 2 sources

Cortex AI Gateway records both agent identity and human delegator context for task-scoped attribution and governance workflows.

Task-scoped delegated control and agent identity attribution mitigate excessive autonomous agency risk patterns.

Teleport · Teleport MCP Access & GovernanceInferred alignmenthigh confidence · 2 sources

Teleport proxies Model Context Protocol (MCP) server traffic and enforces granular role-based access control (RBAC) to allow or block specific tool calls based on string, regex, or glob patterns.

AuditaAI assessment: Proxying MCP connections and applying tool allowlists limits excessive agency in agent tool execution.

Zenity · Runtime Boundaries and AIDRInferred alignmenthigh confidence · 2 sources

Zenity identity-aware runtime boundaries can prevent sensitive data access and exposure by over-permissioned agents.

Preventing over-permissioned agent access to sensitive data aligns with OWASP sensitive-disclosure mitigation context.

LLM07:2025

System Prompt Leakage

System prompts or related sensitive instructions are disclosed.

0 reviewed alignments

No reviewed offering alignments yet.

LLM08:2025

Vector and Embedding Weaknesses

Vector, embedding, or retrieval components create exploitable weaknesses.

0 reviewed alignments

No reviewed offering alignments yet.

LLM09:2025

Misinformation

LLM output creates or propagates false or misleading information.

0 reviewed alignments

No reviewed offering alignments yet.

LLM10:2025

Unbounded Consumption

LLM use creates uncontrolled resource consumption or denial-of-service conditions.

1 reviewed alignment
Reviewed offering assessments+
Snowflake Inc. · Cortex AI GatewayInferred alignmenthigh confidence · 2 sources

Cortex AI Gateway provides centralized token and API-consumption visibility with spend governance controls to reduce runaway enterprise AI usage.

Spend limits and centralized usage governance align with controls for unbounded consumption risk.