All skills
semgrep avatar

/llm-security

@327da93 official
by semgrepsemgrep/skills317 stars
31

Security guidelines for LLM applications based on OWASP Top 10 for LLM 2025. Use when building LLM apps, reviewing AI security, implementing RAG systems, or asking about LLM vulnerabilities like 'prompt injection' or 'check LLM security'. IMPORTANT: Always consult this skill when building chatbots, AI agents, RAG pipelines, tool-using LLMs, agentic systems, or any application that calls an LLM API (OpenAI, Anthropic, Gemini, etc.) — even if the user doesn't explicitly mention security. Also use when users import 'openai', 'anthropic', 'langchain', 'llamaindex', or similar LLM libraries.

Use this Skill: https://skilld.dev/gh/semgrep/skills/llm-security

This session only. Nothing lands on disk.

README.md

≈847 tokens on demand. Your agent reads this file only when SKILL.md points to it.

LLM Security Skill

Security guidelines for LLM applications based on the OWASP Top 10 for Large Language Model Applications 2025.

Categories (10 Total)

Critical Impact

  • LLM01: Prompt Injection - Input validation, content segregation, output filtering
  • LLM02: Sensitive Information Disclosure - Data sanitization, PII detection, permission-aware RAG
  • LLM03: Supply Chain - Model verification, safetensors, ML-BOM
  • LLM04: Data and Model Poisoning - Training data validation, anomaly detection
  • LLM05: Improper Output Handling - Context-aware encoding, parameterized queries

High Impact

  • LLM06: Excessive Agency - Least privilege, human-in-the-loop, rate limiting
  • LLM07: System Prompt Leakage - External guardrails, no secrets in prompts
  • LLM08: Vector and Embedding Weaknesses - Permission-aware retrieval, tenant isolation
  • LLM09: Misinformation - RAG, fact verification, confidence scoring
  • LLM10: Unbounded Consumption - Input limits, budget controls, model theft detection

Structure

llm-security/
├── SKILL.md           # Skill definition (loaded by agents)
├── rules/             # Security rule files
│   ├── _sections.md   # Index of all categories
│   ├── prompt-injection.md
│   ├── sensitive-disclosure.md
│   └── ...            # 10 rule files total
└── README.md          # This file

Usage

For End Users

Install the skill:

npx skills add semgrep/skills

The agent will automatically reference these guidelines when building or reviewing LLM applications.

For Contributors

From the repo root:

make validate    # Validate all skills
make build       # Build all skills
make zip         # Create distribution packages
make             # All of the above

Or for this skill only:

cd packages/skill-build
pnpm install
pnpm validate llm-security      # Validate rule files
pnpm build-agents llm-security  # Build AGENTS.md

Creating a New Rule

  1. Create rules/{category}.md
  2. Follow this structure:
---
title: Category Title
impact: HIGH
impactDescription: Brief description of the impact
tags: security, llm, category-name, owasp-llmXX
---

## Category Title

Brief explanation of the vulnerability.

**Vulnerable (description):**

```python
# Vulnerable code
```

**Secure (description):**

```python
# Secure code
```
  1. Add entry to rules/_sections.md
  2. Run make validate to check formatting
  3. Run make to rebuild everything

Impact Levels

Level Description
CRITICAL Data exfiltration, model compromise, unauthorized actions
HIGH Information disclosure, service degradation, significant risk

Related Frameworks

  • OWASP Top 10 for LLM Applications 2025 - Primary source
  • MITRE ATLAS - Adversarial Threat Landscape for AI Systems
  • NIST AI RMF - AI Risk Management Framework

References

Acknowledgments

Created by @DrewDennison at Semgrep.

Rules derived from the OWASP Top 10 for LLM Applications 2025.

Source: SKILL.md on GitHub

1 alert16d5 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The skill provides comprehensive security guidelines and code examples for building secure LLM applications, based on the OWASP Top 10 for LLMs 2025. It serves as an educational resource to help developers mitigate risks like prompt injection and sensitive data exposure. While the skill contains examples of vulnerable code with hardcoded credentials, these are clearly labeled as insecure patterns for demonstration and educational purposes, using non-functional example values.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: MEDIUM · 1 issue

  • Runlayer6mo

    12/14 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 327da93. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 months ago.

Steadyupdated 7 months ago
  • llm-security
  • prompt-injection
  • owasp
  • rag
  • ai-agents
  • data-poisoning
  • sensitive-disclosure
  • output-handling
  • vector-embeddings

README badge

README badge for semgrep/skills/llm-security

Provides security guidelines for LLM applications based on OWASP Top 10 for LLM 2025, covering prompt injection, sensitive disclosure, data poisoning, excessive agency, and other LLM-specific risks. Use when building chatbots, RAG systems, AI agents, or any application calling LLM APIs to identify relevant vulnerabilities and apply secure patterns.

Generated from the current SKILL.md.

Does this skill cover prompt injection attacks?
Yes. Prompt Injection (LLM01) is a critical category with dedicated rules for preventing both direct and indirect prompt manipulation in chatbots, RAG systems, and tool-using LLMs.
What LLM APIs and libraries does this apply to?
This skill applies to any application calling OpenAI, Anthropic, Gemini, or similar LLM APIs, and to code using LangChain, LlamaIndex, or comparable LLM frameworks.
Should I use this skill only when the user explicitly asks about security?
No. The skill is designed for proactive use: automatically check for relevant security risks whenever building or reviewing LLM applications, chatbots, RAG pipelines, or AI agents — regardless of whether the user mentions security.
Does this cover RAG system security?
Yes. RAG systems have priority rules for Vector/Embedding Weaknesses (LLM08), Prompt Injection (LLM01), Sensitive Disclosure (LLM02), and Misinformation (LLM09).
Are there code examples for each vulnerability?
Yes. Each of the 10 OWASP categories has a dedicated rule file in `rules/` with vulnerable and secure code examples.

Generated from the current SKILL.md. These answers refresh after source changes.