EresusSecurity
ComplianceOWASP LLM

OWASP LLM

Sentinel findings can be triaged using the OWASP Top 10 for LLM Applications v2025 risk language. This page maps rule IDs to risk categories that management, AppSec, and engineering can share.

Definition

OWASP LLM mapping connects Sentinel rule IDs to the LLM01-LLM10 risk language, giving executive summaries, compliance reports, and engineering issues a shared vocabulary.

Mapping

OWASPRiskSentinel coverage
LLM01:2025Prompt InjectionPrompt firewall, Jinja2 templates, GGUF chat templates
LLM02:2025Sensitive Information DisclosureSecrets, output firewall, RAG fixtures, logs
LLM03:2025Supply ChainArtifact scanners, HuggingFace intake, OCI, CVE, manifests
LLM04:2025Data and Model PoisoningModel provenance, manifest integrity, suspicious metadata
LLM05:2025Improper Output HandlingOutput firewall, template rendering, downstream code paths
LLM06:2025Excessive AgencyMCP permissions, tool manifests, network egress
LLM07:2025System Prompt LeakagePrompt fixtures, template secret exposure, output guardrails
LLM08:2025Vector and Embedding WeaknessesRAG context leakage, poisoned documents, retrieval boundaries
LLM09:2025MisinformationEval evidence, model provenance, report review workflow
LLM10:2025Unbounded ConsumptionSize limits, archive ratio, tensor dimensions, model DoS

Source: OWASP Top 10 for LLM Applications v2025.

Workflow

Compliance checking is not a pentest by itself, but it shows which AI risk class is supported by which technical finding. Use OWASP labels in executive summaries and Sentinel rule IDs in technical appendices.

sentinel compliance check . --framework owasp-llm

Coverage boundaries

Sentinel strengthens static signals, artifact safety, prompt/agent checks, and CI evidence. Live exploit chains, business-logic abuse, and human approval flows still require manual security validation.

Eresus support

Turn the finding into an action your team can actually close.

If you need exploit evidence, prioritization, remediation direction, and retesting for OWASP LLM and AI security compliance, Eresus can help scope the work with your team.

Start Security Test