Skip to main content

OWASP Top 10 for LLM Applications External Framework Crosswalk

Generated Evaluation Status

This section is generated from the framework manifest and compatibility report. Do not edit it manually.

  • Framework ID: owasp-top-10-llm
  • Manifest: docs/external-frameworks/owasp-top-10-llm.json
  • Compatibility report: ./reports/owasp-top-10-llm.compatibility.json
  • Evidence class: SOURCE_REVIEWED
  • Independently reproducible: False
  • Comparative-testing claim allowed: False
  • Missing reproducibility gates: shared_test_vector, raw_output, timestamp, runtime_configuration, source_version_or_hash, replay_commands, declared_expected_outcome, independent_reproduction
  • Evaluation result: COMPATIBILITY_EVIDENCE_ONLY
  • Cycle status: FIRST_FRAMEWORK_CYCLE_COMPLETE
  • Execution authority claim: False
  • Next bounded action: Add executable observations, raw outputs, pinned versions, replay commands, and independent reproduction before making comparative-testing claims.
  • Posting source: generated compatibility report
  • Generated status is descriptive compatibility evidence only.

Generated Authored Analysis Boundary

This section is generated. Do not edit it manually.

  • Framework ID: owasp-top-10-llm
  • Framework name: OWASP Top 10 for LLM Applications
  • Generated sections above this boundary may be rebuilt from registry, manifest, compatibility-report, and result artifacts.
  • Authored analysis below this boundary may contain interpretation, notes, and framework-specific discussion.
  • Generators must preserve authored analysis unless a future validator explicitly declares a migration path.
  • Boundary rule: generated material is descriptive compatibility evidence only and does not create certification, endorsement, adoption, proof, or operational permission.

Generated Transition Mapping

This section is generated from the framework manifest. Do not edit it manually.

FieldGenerated Value
framework_identityOWASP Top 10 for LLM Applications
source_referencehttps://owasp.org/www-project-top-10-for-large-language-model-applications/
source_versionpublic source recorded
allowed_use_boundaryLLM-application risk and vulnerability guidance crosswalk evidence only
claimsrisk categories, vulnerability classes, mitigation guidance, and LLM application security review context
non_claimsno admissibility proof, certification, endorsement, execution authority, or commit-time authority
input_artifact_typerisk category, vulnerability, mitigation, or application-security guidance reference
output_artifact_typecrosswalk and compatibility evidence
actor_or_authority_modelexternal security-guidance posture; no StegVerse authority inherited
evidence_modelrisk categories, vulnerability descriptions, mitigations, and supporting control context
policy_or_rule_modelmitigation and risk-control policy reference comparison
delegation_modelnot asserted by wiki entry
decision_or_result_modelrisk-context evidence only
execution_authority_claimfalse
receipt_or_trace_modelsource reference and wiki record
reconstruction_modelsource plus crosswalk can reconstruct LLM-application risk-context relationship limits
SPE_overlapmay inform evidence and review posture, not standing determination
StegVerse_ecosystem_overlapEvidence Posture, Review Posture, Governance Boundary, Drift, Policy Reference, Fail-Closed behavior
fail_closed_conditionsmissing source, undefined mapping, stale risk context, unresolved mitigation status, or authority overclaim

Generated mapping is compatibility evidence only.

Generated Framework Metadata

This section is generated from the external-framework registry. Do not edit it manually.

  • Framework ID: owasp-top-10-llm
  • Name: OWASP Top 10 for LLM Applications
  • Registry status: SOURCED-CROSSWALK-PROVISIONAL
  • Testbench state: SOURCE_RECORDED_CROSSWALK_PROVISIONAL
  • Manifest path: docs/external-frameworks/owasp-top-10-llm.json
  • Source reference: https://owasp.org/www-project-top-10-for-large-language-model-applications/
  • Metadata boundary: generated metadata is descriptive only; it does not create certification, endorsement, formalism adoption, admissibility proof, or execution authority.

Status

Relationship type: external framework crosswalk
Canonical StegVerse formalism source: Admissible-Existence
External framework role: LLM application risk and vulnerability guidance
Wiki role: risk-control observatory, evidence comparison, and relationship review
Citation status: sourced
Evidence provenance status: Batch 3 refactor installed

Source

Official source: https://owasp.org/www-project-top-10-for-large-language-model-applications/

The official source is treated as the canonical public source for OWASP Top 10 for LLM Applications framing.

Evidence Provenance

Evidence ClassCurrent EvidenceStatusMissing Fields
Official Framework SourcesOfficial OWASP project source URL.presentVersioned source snapshot and source hash.
Official Implementation SourcesOWASP Top 10 for LLM Applications is treated here as external guidance rather than a runtime implementation.not_applicable_or_external_guidanceSpecific version/snapshot if used in a test.
Observed BehaviorNo runtime behavior is claimed.not_applicable_for_runtime_resultNot a runtime-result page.
Reproduced BehaviorNo independent reproduction is claimed.not_applicableReproduction only if a mapping fixture is created.
StegVerse AnalysisRisk categories, prompt injection, output handling, mitigations, and application security review are mapped to admissibility primitives.risk_category_crosswalkConcrete Commitment Candidate fixture with risk-category references.
Interoperability AssessmentOWASP risk evidence may support review posture, not authority.pending_mapping_to_application_review_postureFixture and compatibility report.
StandingSourced provisional.provisionalSource snapshot and mapping artifact.

Evidence classification:

F1: official OWASP project source URL and framework-native guidance claims.
S1: StegVerse interpretation of OWASP LLM risk categories as review-context evidence.
S2: mapping to Review Posture, Evidence Posture, Governance Boundary, Drift, Fail-Closed behavior, Commit-Time Validity, Receipt-Bound Execution, Policy Reference, Boundary Conditions, and Reconstructability.
H1: future mapping fixture until concrete risk-category references are attached.

Definition

OWASP Top 10 for LLM Applications is treated in this wiki as an external LLM-application risk and vulnerability guidance framework.

It is not treated as an admissibility engine, execution-authority source, certification authority, or commit-time standing proof.

Framework-Term Definitions

Native OWASP TermDefinition For This WikiReconciliation ClassAdmissibility Relationship
OWASP Top 10 for LLM ApplicationsExternal LLM-application risk and vulnerability guidance framework.newPreserved as framework-native terminology.
Top 10 risk categoryPublished risk or vulnerability category for LLM applications.adjacentRelated to Review Posture and Evidence Posture.
Prompt injectionAttack class where model instructions or context are manipulated to alter behavior.adjacentRelated to Governance Boundary, Drift, and Fail-Closed behavior.
Insecure output handlingRisk where model output is trusted or acted on without sufficient controls.adjacentRelated to Commit-Time Validity and Receipt-Bound Execution.
Mitigation guidanceRecommended control or practice for reducing an identified LLM-application risk.adjacentRelated to Policy Reference and Boundary Conditions.
LLM application security reviewReview of application-level risks around an LLM system.adjacentSupports Review Posture but does not replace SPE standing determination.

Relationship To Admissibility

OWASP Top 10 for LLM Applications is listed as a crosswalk target for LLM-application risk, vulnerability, and mitigation context.

Admissibility review remains separate and asks whether a proposed transition may bind consequence at commit time.

In StegVerse terms, OWASP evidence may support a Commitment Candidate by identifying risk category, vulnerability class, mitigation expectation, and control gap context. Those records remain evidence. They do not become execution authority.

Crosswalk Targets

OWASP Candidate FunctionWiki / AE Relationship
Risk category classificationReview Posture; Evidence Posture
Prompt-injection analysisGovernance Boundary; Drift; Fail-Closed behavior
Output-handling reviewCommit-Time Validity; Receipt-Bound Execution
Mitigation mappingPolicy Reference; Boundary Conditions
Application security reviewReview Posture; Reconstructability

Three-Part Boundary

OWASP asks: Which LLM-application risks or mitigations are relevant?
Admissibility asks: May this transition bind consequence at commit time?
EVIDE asks: What evidence remains after the event?

Non-Claims

OWASP Top 10 for LLM Applications is not a StegVerse canonical formalism.
OWASP Top 10 for LLM Applications does not prove transition admissibility.
OWASP Top 10 for LLM Applications does not grant execution authority inside StegVerse.
OWASP source citation is not acceptance of equivalence.
Security-risk review may support evidence and review posture, but review does not become authority.

Challenge Path

A reader may challenge this reflection by identifying the claim, challenged field, reason, supporting evidence, and requested correction or standing change.

This page reflects a bounded admissibility packet. Publication does not create standing. The reflected claim inherits only the standing that can be reconstructed from the referenced evidence, authority, and admissibility conditions.

Next Safe Build Target

Connect OWASP risk categories to the governance observatory protocol and test whether LLM-application risk evidence can be routed into a Commitment Candidate without granting execution authority to the risk record itself.