← Blog

OWASP

12 articles about "OWASP".

AI 安全LLM EvaluationOutput ScanningRegexTesting開源OWASP

Regex Can't Tell "Said It" From "Warned Against It": False Positives, Misses, and Our Overturned Fix in LLM Output Scanning

Matching LLM replies with regex to catch XSS or SQL injection strings also fails replies that name the hazard in order to warn against it: on an unmerged open-source Giskard PR, all 5 such advice sentences tripped the check. We proposed anchoring the patterns to line start and false positives fell to 0. Then the PR author added one ordinary phrasing, a lead-in on the same line as the payload, and the anchor missed 12 of 24 compliant replies. This post covers why the anchor only held on our sample, how to choose between over-reporting and under-reporting, and why our own output scanner has the same limit.

· 17 min read
AI 安全Prompt InjectionAgent SkillsClaude CodeAI One-Person CompanyOWASP

AI Skills Are an Injection Path Too: Scanning 954 Popular Skills, and an Eighth Question Before Buying an AI System

A September 2026 paper scanned 954 popular AI agent skills. Its tool flagged 17.6%, and reviewers confirmed 84 of 100 sampled findings as latent vulnerabilities. Five skills were attacked for real and 13 of 30 attempts succeeded, even when models recognised the risk. Around the same time Microsoft disclosed two 9.9-rated Semantic Kernel vulnerabilities, and both arrive at the same line: the model is not a security boundary. This post unpacks the qualifiers on each number and adds an eighth question to our seven questions to ask before buying an AI one-person-company system.

· 9 min read
AI 安全AI AgentRed TeamingPrompt InjectionPyRITInfoSecOWASP

Why Agentic AI Attack Testing Shouldn't Be One Class Per Attack: The Vector / Framing / Scorer Decomposition

In an agent pipeline the same malicious payload can enter as a tool result, a retrieved document, or a sub-agent message. Write one attack class per entry point and your test harness explodes. This is the three-axis model we posted publicly in microsoft/PyRIT: injection vector is data, framing is a transform, the scorer is the verdict, and why an attack is a placement, not a message.

· 17 min read
OWASPAI 安全AI AgentPrompt Injectionasi-top10

OWASP Agentic Top 10 (ASI-01 to ASI-10) Explained for 2026: Real Scenarios, Detection and a Fix Checklist for Each Risk

A risk-by-risk breakdown of the OWASP Agentic Top 10 (ASI-01 to ASI-10): what each risk is, what a real scenario looks like, how to scan for it with open-source tools, and a fix checklist you can copy directly. Written for people actually running AI agents.

· 15 min read
OWASPAI 安全llm-securityPrompt InjectionAI Agent

OWASP LLM Top 10 Explained (Official 2025 Edition, 2026 Status): How It Differs from the Agentic ASI Top 10 and How Developers Should Defend

Which list should you read when you search for "OWASP LLM Top 10 2026"? The latest official version is still the 2025 edition; what is new in 2026 is the Agentic ASI attack surface. This post walks through all 10 risks one by one, compares LLM and Agentic security, and gives developers three layers of defense they can put into practice.

· 11 min read
MCPPrompt InjectionAI 安全OWASP開源BuildInPublic

We Audited 7 Official MCP Servers: 6 Got F

Ran prompt-defense-audit against the 7 official servers in modelcontextprotocol/servers: 12-vector check, OWASP LLM Top 10 mapping. Result: 6 servers scored F, 8 defense vectors at 100% gap rate. Cross-referenced from modelcontextprotocol/servers#3537.

· 9 min read
OWASPAI 安全AI AgentPrompt Injectioncompliance

OWASP Agentic Top 10: What Every AI Developer Needs to Know in 2026

OWASP released its Top 10 security risks for AI agent applications in 2026. We break down each risk with real data from scanning 1,646 production system prompts.

· 8 min read
AI 安全Open StandardOWASPAEOSEOPII開源UltraProbe

We Defined an AI Security Standard: AASS v1.0, We Don't Sell Security, We Define It

AI Application Security Standard (AASS) is the first open standard covering AI system defense, website AI visibility, and data protection in a single framework. All tools free and open source.

· 1 min read
AI 安全LLMPrompt InjectionOWASPUltraProbeInfoSec

Prompt Injection Isn't Your Biggest Risk: We Scanned 517 AI System Prompts and Found 11 Undefended Attack Vectors

Everyone talks about Prompt Injection, but it's just 1 of 12 LLM attack vectors. We scanned 517 AI system prompts with UltraProbe and found they defend against only 3.2 of the 12 on average. Here are the other 11 you're ignoring.

· 13 min read
AI 安全OWASPPrompt InjectionAI AgentData Analysis開源

78.3% Score F: Prompt Defense Gap Data from 1,646 Real AI System Prompts

We scanned 1,646 system prompts leaked from GPT Store, ChatGPT, Claude, Cursor and others. The average score was 36/100 and 78.3% scored F. This post uses the data to show how serious each OWASP Agentic Top 10 risk is in the real world.

· 12 min read
AI 安全開源Prompt InjectionLLMOWASPnpm

We Open-Sourced Our Prompt Defense Scanner: 200 Lines of Regex That Replace an LLM

Most AI security tools use LLMs to check LLMs. We built a deterministic prompt defense scanner: 12 attack vectors, pure regex, under 1ms, zero cost. Here's why regex beats AI for this job, and how you can use it today.

· 11 min read
AI 安全Prompt InjectionOWASPLLMSecurity Tools

UltraProbe Is Live: The World's First Free AI Security Scanner That Finds Your LLM Vulnerabilities in 5 Seconds

90% of AI systems are vulnerable to Prompt Injection, yet most developers have no idea. Ultra Lab launches the completely free UltraProbe, covering the OWASP LLM Top 10 attack vectors, making AI security testing accessible to everyone, not just enterprises.

· 10 min read