LLM feature risk check
Five questions about what your AI feature reads and what it can do. The result lists the OWASP LLM risks that apply and the controls for each.
For chatbots, assistants, RAG and agents. The risks that matter depend on two things: what text the model reads, and what it is allowed to do.
On its way
Check your inbox shortly. If you would rather talk it through, book a time.
How the check works
The OWASP Top 10 for LLM applications lists ten risks, but which ones matter for a feature depends on two things. The first is what the model reads: anything an outsider can influence, such as web pages, uploaded files or inbound email, is a route for indirect prompt injection. The second is what the model can do: a model that only answers can embarrass you, while one that can change records, send messages or move money can cause an incident. Where both are true, the risk is high whatever the prompt says.
The check also flags data disclosure when the model reads customer records, retrieval weaknesses when it searches stored documents, and cost abuse when there are no usage limits. Every feature gets output handling and system prompt leakage, because they apply to all of them. The recommendation follows from the combination: an assessment for features that read data, and red teaming as well when untrusted content meets actions. See excessive agency for why that combination matters most.
Common questions
Is a feature that only answers questions safe?
Safer. Prompt injection and disclosure still apply if it reads customer data.
Which risk matters most?
Untrusted content combined with actions. That pairing turns an injection into an incident.