01Introduction
Teams are shipping chatbots, copilots and agents that read untrusted content and call real tools. That gives attackers a new interface: plain language. A single instruction hidden in a web page or support ticket can turn a helpful assistant into a data exfiltration tool.
02What is LLM security?
LLM application security covers the risks specific to software built on large language models, cataloged in the OWASP Top 10 for LLM Applications: prompt injection, sensitive information disclosure, excessive agency, insecure output handling, supply chain risks and more.
It differs from AI-SPM, which secures the models and AI infrastructure in your cloud, and from AI-generated code security, which is about code written by assistants. This is about the apps you build on top of models.
03How LLM security works
Securing an LLM app means treating the model as untrusted.
- 1.
Map inputs
Identify every source of text the model reads, including user prompts, documents, web pages, emails and tool results.
- 2.
Limit agency
Give tools the narrowest permissions and require confirmation for destructive actions.
- 3.
Handle output safely
Treat model output like user input before rendering it, querying with it or executing it.
- 4.
Test adversarially
Attempt direct and indirect prompt injection, jailbreaks and exfiltration through links, images or tool calls.
04Threats and risks
LLM risks combine old and new attack classes.
Prompt injection
Instructions in user input or retrieved content override the system prompt.
Tool abuse
An agent with broad API access is talked into deleting, sending or purchasing.
Data exfiltration
Secrets or other users' data leak through responses, rendered markdown or outbound requests.
Classic bugs, new path
Model output passed to SQL, shells or HTML reintroduces injection and XSS.
05How Parameter helps
Parameter AI Pentesting tests AI and LLM apps as part of the same engagement.
Prompt injection testing
Agents attempt direct and indirect injection through every input the model reads.
Tool and data abuse
Agents check whether the assistant can be steered into calling tools or leaking data it should not.
Full-stack context
LLM findings are tested alongside the APIs and auth the assistant sits on, where the real impact lives.

