Prompt Injection Testby Agent Trust Cloud

OWASP LLM01: prompt injection

The OWASP Top 10 for LLM Applications 2025 ranks prompt injection first. This page summarises the LLM01:2025 entry in our own words and shows how the prompt injection test maps to it.

The 2025 list

IDRisk
LLM01:2025Prompt Injection
LLM02:2025Sensitive Information Disclosure
LLM03:2025Supply Chain
LLM04:2025Data and Model Poisoning
LLM05:2025Improper Output Handling
LLM06:2025Excessive Agency
LLM07:2025System Prompt Leakage
LLM08:2025Vector and Embedding Weaknesses
LLM09:2025Misinformation
LLM10:2025Unbounded Consumption

What LLM01 covers

The nine scenarios

Direct injection · Indirect injection · Unintentional injection · Intentional model influence · Code injection · Payload splitting · Multimodal injection · Adversarial suffix · Multilingual or obfuscated attack. Each is summarised with its documented case on the examples page.

The seven mitigations

  1. Constrain model behaviour
  2. Define and validate expected output formats
  3. Implement input and output filtering
  4. Enforce privilege control and least privilege access
  5. Require human approval for high-risk actions
  6. Segregate and identify external content
  7. Conduct adversarial testing and attack simulations

How to apply each one: how to prevent prompt injection attacks.

Related entries

EntryHow it connects to LLM01Test family
LLM02 Sensitive Information DisclosureWhat an injection often extractsTool-call exfiltration, secret disclosure
LLM05 Improper Output HandlingRendered links and images, or executed output, carry the attack furtherMarkdown image and link exfiltration
LLM06 Excessive AgencyTools and permissions decide how much damage an injection doesTool-call exfiltration
LLM07 System Prompt LeakageAnything in the prompt can be extractedSecret and system prompt disclosure

Map your agent's defences to LLM01

Sources

Questions

What is OWASP LLM01?

LLM01:2025 Prompt Injection is the first entry in the OWASP Top 10 for LLM Applications 2025. It covers inputs, direct or from external content, that alter a model's behaviour in unintended ways.

Which OWASP entries relate to LLM01?

LLM02 Sensitive Information Disclosure, LLM05 Improper Output Handling, LLM06 Excessive Agency and LLM07 System Prompt Leakage describe what an injection can lead to or exploit.