Skip to main content

OWASP Top 10 for LLM Applications External Framework Crosswalk

Generated Evaluation Status

This section is generated from the framework manifest and compatibility report. Do not edit it manually.

  • Framework ID: owasp-top-10-llm
  • Manifest: docs/external-frameworks/owasp-top-10-llm.json
  • Compatibility report: ./reports/owasp-top-10-llm.compatibility.json
  • Evidence class: SOURCE_REVIEWED
  • Independently reproducible: False
  • Comparative-testing claim allowed: False
  • Missing reproducibility gates: shared_test_vector, raw_output, timestamp, runtime_configuration, source_version_or_hash, replay_commands, declared_expected_outcome, independent_reproduction
  • Evaluation result: COMPATIBILITY_EVIDENCE_ONLY
  • Cycle status: FIRST_FRAMEWORK_CYCLE_COMPLETE
  • Execution authority claim: False
  • Next bounded action: Add executable observations, raw outputs, pinned versions, replay commands, and independent reproduction before making comparative-testing claims.
  • Posting source: generated compatibility report
  • Generated status is descriptive compatibility evidence only.

Generated Authored Analysis Boundary

This section is generated. Do not edit it manually.

  • Framework ID: owasp-top-10-llm
  • Framework name: OWASP Top 10 for LLM Applications
  • Generated sections above this boundary may be rebuilt from registry, manifest, compatibility-report, and result artifacts.
  • Authored analysis below this boundary may contain interpretation, notes, and framework-specific discussion.
  • Generators must preserve authored analysis unless a future validator explicitly declares a migration path.
  • Boundary rule: generated material is descriptive compatibility evidence only and does not create certification, endorsement, adoption, proof, or operational permission.

Generated Transition Mapping

This section is generated from the framework manifest. Do not edit it manually.

FieldGenerated Value
framework_identityOWASP Top 10 for LLM Applications 2025 / OWASP GenAI Security Project
source_referencehttps://genai.owasp.org/resource/owasp-top-10-for-llm-applications-2025/
source_version2025 list
allowed_use_boundaryLLM/GenAI application risk and vulnerability guidance crosswalk evidence only
claimsrisk categories, vulnerability classes, mitigation guidance, and LLM/GenAI application security review context
non_claimsno admissibility proof, certification, endorsement, standing, execution authority, or commit-time authority
input_artifact_typerisk category, vulnerability, mitigation, or application-security guidance reference
output_artifact_typecrosswalk and bounded StegVerse governance compatibility evidence
actor_or_authority_modelexternal security-guidance posture; no StegVerse authority inherited
evidence_modelrisk categories, vulnerability descriptions, mitigations, and supporting control context
policy_or_rule_modelmitigation and risk-control policy reference comparison
delegation_modelnot established by OWASP guidance
decision_or_result_modelrisk-context evidence only
execution_authority_claimfalse
receipt_or_trace_modelofficial OWASP source set plus wiki manifest, fixture, and generated validation reports
reconstruction_modelversioned resource plus crosswalk reconstructs the security-risk relationship and its limits
SPE_overlapmay inform evidence and review posture, not standing determination
StegVerse_ecosystem_overlapEvidence Posture, Review Posture, Governance Boundary, Drift, Policy Reference, Receipt-Bound Execution, Fail-Closed behavior
fail_closed_conditionsmissing source identity, wrong list version, stale risk context, unresolved mitigation status, semantic scope divergence, or authority overclaim

Generated mapping is compatibility evidence only.

Generated Framework Metadata

This section is generated from the external-framework registry. Do not edit it manually.

  • Framework ID: owasp-top-10-llm
  • Name: OWASP Top 10 for LLM Applications
  • Registry status: SOURCED-CROSSWALK-PROVISIONAL
  • Testbench state: SOURCE_RECORDED_CROSSWALK_PROVISIONAL
  • Manifest path: docs/external-frameworks/owasp-top-10-llm.json
  • Source reference: https://owasp.org/www-project-top-10-for-large-language-model-applications/
  • Metadata boundary: generated metadata is descriptive only; it does not create certification, endorsement, formalism adoption, admissibility proof, or execution authority.

Status

Relationship type: external framework crosswalk
Canonical StegVerse formalism source: Admissible-Existence
External framework role: LLM/GenAI application risk and vulnerability guidance
Current evaluated resource: OWASP Top 10 for LLM Applications 2025
Current broader project: OWASP GenAI Security Project
Evidence posture: VERSIONED_PUBLIC_GUIDANCE + BOUNDED_STEGVERSE_CROSSWALK
Runtime posture: NOT_APPLICABLE_AS_AUTHORITY_ENGINE
Standing: no standing created
Execution authority: none

Official Source And Version

This evaluation is pinned to the OWASP Top 10 for LLM Applications 2025 resource and records the OWASP GenAI Security Project as the current broader project context.

2025 resource: https://genai.owasp.org/resource/owasp-top-10-for-llm-applications-2025/
current project: https://genai.owasp.org/
project evolution: https://genai.owasp.org/2025/03/26/project-owasp-promotes-genai-security-project-to-flagship-status/
evaluated list: 2025 Top 10 Risk & Mitigations for LLMs and Gen AI Apps

The evaluated LLM/GenAI Top 10 remains distinct from the later OWASP Top 10 for Agentic Applications. Project evolution does not silently change the identity of the evidence used by this crosswalk.

Evidence Provenance

Evidence ClassCurrent EvidenceStatusMissing Fields
Official Framework SourcesVersioned OWASP Top 10 for LLM Applications 2025 resource plus current OWASP GenAI Security Project context.present_versioned_public_guidanceNo source-identity gap for the bounded 2025-list crosswalk.
Official Implementation SourcesOWASP Top 10 is security guidance rather than an authorization runtime implementation.not_applicable_external_guidanceA target application's implementation evidence must be evaluated separately.
Observed BehaviorNo native OWASP runtime authorization or consequence-binding behavior is claimed.not_applicable_for_runtime_resultRuntime behavior is not a property of the guidance document itself.
Reproduced BehaviorNo independent runtime reproduction is claimed.not_applicable_for_runtime_resultTarget-specific security testing would be a separate evidence packet.
StegVerse AnalysisRisk categories and mitigations are mapped to Evidence Posture, Review Posture, Governance Boundary, Drift, Policy Reference, Receipt-Bound Execution, and Fail-Closed behavior.risk_category_crosswalkCanonical merged-state validation remains the local gate.
Interoperability AssessmentSix StegVerse case families test whether risk evidence can influence review without becoming identity, delegation, standing, or authority.bounded_crosswalk_pending_merged_validationNo OWASP certification or endorsement is claimed.
StandingSecurity guidance and this page create no standing.none_createdStanding must be independently reconstructed at the governed transition.

Evidence classification:

F1: official OWASP Top 10 for LLM Applications 2025 resource and current OWASP GenAI Security Project context.
S1: StegVerse interpretation of OWASP LLM/GenAI risk categories and mitigations as security-review evidence rather than authority.
S2: six-family StegVerse mapping to Evidence Posture, Review Posture, Governance Boundary, Drift, Policy Reference, Receipt-Bound Execution, and Fail-Closed behavior.
H1: any claim that OWASP guidance itself proves target security, grants standing, establishes delegation, certifies StegVerse, or authorizes consequence remains prohibited unless separately evidenced.

Framework-Term Definitions

Native OWASP TermDefinition For This WikiReconciliation ClassAdmissibility Relationship
OWASP Top 10 for LLM ApplicationsVersioned external LLM/GenAI application risk and vulnerability guidance; this evaluation is pinned to the 2025 list.newPreserved as framework-native security terminology; not an admissibility engine.
Top 10 risk categoryPublished class of LLM/GenAI application security risk.adjacentSupports Review Posture and Evidence Posture.
Prompt injectionAttack class in which instructions or context are manipulated to influence model/application behavior.adjacentRelated to Governance Boundary, Drift, scope integrity, and Fail-Closed behavior.
Insecure output handlingRisk arising when model output is insufficiently validated or constrained before downstream use.adjacentRelated to Commit-Time Validity and Receipt-Bound Execution.
Mitigation guidanceRecommended practice or control intended to reduce an identified risk.adjacentMay inform Policy Reference and Boundary Conditions; recommendation is not proof of implementation or effectiveness.
LLM application security reviewReview of security risks and mitigations around an LLM/GenAI application.adjacentSupports Review Posture and Reconstructability; review does not become authority.
OWASP GenAI Security ProjectCurrent broader OWASP project context containing multiple GenAI security resources.newContext for source lineage; broader project scope must not silently alter the evaluated resource identity.
Agentic Applications Top 10Separate OWASP resource addressing agentic-system risks.distinctMust not be conflated with the evaluated 2025 LLM/GenAI Top 10 evidence packet.

What The Framework Claims And Demonstrates

The 2025 OWASP Top 10 provides security-risk categories, vulnerability descriptions, and mitigations for LLM and generative-AI applications. The broader GenAI Security Project publishes additional security resources, but this evaluation does not treat those resources as one undifferentiated authority source.

OWASP risk guidance can identify security-relevant conditions. It does not establish actor identity, delegation, StegVerse standing, commit-time admissibility, or authority to bind consequence.

StegVerse Evidence Installed

The repository contains a bounded six-family governance compatibility contract for this framework. The fixture is StegVerse-authored crosswalk machinery and does not imply that OWASP executed or endorsed StegVerse tests.

manifest: docs/external-frameworks/owasp-top-10-llm.json
governance fixture: tests/fixtures/external-frameworks/owasp-top-10-llm-governance-compatibility-cases.v1.json
case families: 6
simulation_only: true
canonical validation path: .github/workflows/validate-chain-continuation.yml

The six bounded test families cover:

FamilyStegVerse Boundary Tested
positive alignmentRisk context may support ALLOW only if independent authority, policy, scope, freshness, and mitigation predicates are satisfied.
framework denial / negative resultA blocking security condition maps to DENY within the evaluated scope.
authority / delegation failureSecurity guidance cannot restore absent or expired authority.
stale / missing evidenceStale or incomplete risk evidence fails closed.
malformed / undefined resultUndefined mapping or malformed evidence fails closed.
semantic divergence guardEvidence or mitigation for one application scope cannot authorize another scope.

The canonical governance-compatibility validator has observed all six owasp-top-10-llm case families as repository tests. That proves execution of the StegVerse mapping contract, not runtime execution of OWASP guidance.

Governance-Chain Placement

OWASP Top 10 evidence belongs upstream of commitment:

versioned OWASP risk / vulnerability / mitigation reference
-> Evidence Posture + Review Posture + Governance Boundary context
-> candidate policy / mitigation expectations
-> independent standing + delegation + scope + freshness reconstruction
-> commit-time admissibility decision
-> consequence binding only when separately authorized

A risk classification can strengthen or weaken the evidence available to an admissibility gate. It does not become execution authority merely because it is security-relevant.

Claims Versus Demonstrated Abilities

QuestionCurrent Evidence
Is a specific OWASP resource identified?Yes: Top 10 for LLM Applications 2025.
Is current broader project context recorded?Yes: OWASP GenAI Security Project.
Is the Agentic Top 10 kept distinct?Yes.
Are risk and mitigation concepts mappable into review evidence?Yes.
Has StegVerse installed a six-family mapping contract?Yes.
Has the canonical validator exercised those six families?Yes, as StegVerse tests.
Does this prove a production application is secure?No.
Does OWASP guidance establish actor standing or delegation?No.
Is certification or OWASP endorsement claimed?No.
Is execution authority granted?No.

Non-Capabilities And Non-Claims

OWASP Top 10 for LLM Applications is not a StegVerse canonical formalism.
OWASP guidance does not prove transition admissibility.
A risk category does not establish actor identity or delegation.
A mitigation recommendation does not prove that a mitigation is implemented or effective in a specific target.
Security review does not become execution authority.
The StegVerse compatibility fixture is simulation/crosswalk evidence, not OWASP certification or endorsement.
Publication creates no standing.

Current Completion Gate

The versioned source identity, current project context, six-family mapping contract, governance-chain placement, terminology reconciliation, evidence-provenance contract, and non-authority boundaries are installed. The remaining local gate is canonical validation of the merged page/manifest state. If the OWASP-specific manifest, terminology, page, provenance, benchmark, and governance-compatibility checks pass, this evaluation can reach LOCAL_WORK_COMPLETE_BOUNDED_SECURITY_CROSSWALK without inventing runtime or certification evidence.

Challenge Path

A reader may challenge the evaluated resource, version, risk mapping, mitigation interpretation, scope, failure posture, or authority boundary by supplying inspectable evidence for correction.

This page reflects a bounded admissibility packet. Publication does not create standing. The reflected claim inherits only the standing that can be reconstructed from the referenced evidence, authority, and admissibility conditions.