VibeCoded

LLM feature risk check

Five questions about what your AI feature reads and what it can do. The result lists the OWASP LLM risks that apply and the controls for each.

Last reviewed 2026-09-30Written by Jacob Masse, TrazTech Inc.

For chatbots, assistants, RAG and agents. The risks that matter depend on two things: what text the model reads, and what it is allowed to do.

What does the model read?

Tick every source.

What can it do?

Tick every capability.

Do actions need a person to confirm?

Is the app multi-customer?

Are there per-user usage limits?

How the check works

The OWASP Top 10 for LLM applications lists ten risks, but which ones matter for a feature depends on two things. The first is what the model reads: anything an outsider can influence, such as web pages, uploaded files or inbound email, is a route for indirect prompt injection. The second is what the model can do: a model that only answers can embarrass you, while one that can change records, send messages or move money can cause an incident. Where both are true, the risk is high whatever the prompt says.

The check also flags data disclosure when the model reads customer records, retrieval weaknesses when it searches stored documents, and cost abuse when there are no usage limits. Every feature gets output handling and system prompt leakage, because they apply to all of them. The recommendation follows from the combination: an assessment for features that read data, and red teaming as well when untrusted content meets actions. See excessive agency for why that combination matters most.

Get the feature tested

Describe the model, what it reads and what it can do.

Get matched

Common questions

Is a feature that only answers questions safe?

Safer. Prompt injection and disclosure still apply if it reads customer data.

Which risk matters most?

Untrusted content combined with actions. That pairing turns an injection into an incident.