Skip to content
Back to skills

Common Llm Security

ASecurity

**πŸ”΄ LLM01 β€” Prompt Injection: Confirmed, P0**

  • 571 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 24, 2026
developmentrustshellsqlapisecurity

Works with

  • cli
  • api

Security analysis

A100/100

Pro scans all 16 files and shows the line behind each finding

Scanned September 24, 2026

npx -y skills add HoangNguyen0403/agent-skills-standard --skill common-llm-security --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Common Llm Security?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Common Llm Security
[![Security: A β€” Skills Directory](https://www.skillsdirectory.com/api/skills/hoangnguyen0403-common-llm-security-06abcf18/badge)](https://www.skillsdirectory.com/skills/hoangnguyen0403-common-llm-security-06abcf18)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
## Audit result

**πŸ”΄ LLM01 β€” Prompt Injection: Confirmed, P0**

Concatenating the user’s message into the system prompt allows the user to alter or override system instructions. This is a direct prompt-injection vulnerability and caps the security score at **40/100**.

Remediate by keeping the system prompt static and passing user input as a separate `user` message:

```js
const messages = [
  { role: "system", content: SYSTEM_PROMPT },
  { role: "user", content: userMessage }
];

const response = await client.chat.completions.create({
  model: "your-model",
  messages,
  max_tokens: 1000
});
```

Also validate and **sanitize** user input where appropriate, delimit untrusted retrieved content, and never treat user-controlled text as instructions.

## OWASP LLM Top 10 status

- **LLM01 Prompt Injection:** πŸ”΄ Confirmed β€” direct prompt concatenation.
- **LLM02 Sensitive Information Disclosure:** ⚠️ Needs review β€” check whether PII, credentials, system prompts, or unredacted responses enter the prompt or logs.
- **LLM03 Supply Chain:** ⚠️ Needs review β€” verify model, packages, plugins, weights, pinned revisions, and hashes.
- **LLM04 Data & Model Poisoning:** ⚠️ Needs review β€” validate user-controlled data before storing it in training data, memory, or embedding stores.
- **LLM05 Improper Output Handling:** ⚠️ Needs review β€” sanitize model output before using it in the DOM, SQL, shell commands, or redirect URLs.
- **LLM06 Excessive Agency:** ⚠️ Needs review β€” require human confirmation for tools that write, delete, execute, or access networks.
- **LLM07 System Prompt Leakage:** ⚠️ Needs review β€” prevent prompt contents from appearing in tool output, errors, or API responses.
- **LLM08 Vector & Embedding Weaknesses:** ⚠️ Needs review β€” sanitize indexed text and enforce tenant namespace isolation.
- **LLM09 Misinformation:** ⚠️ Needs review β€” independently verify outputs used for medical, financial, legal, or other critical decisions.
- **LLM10 Unbounded Consumption:** ⚠️ Needs review β€” set `max_tokens`, rate-limit requests, and cap agent loop depth or iterations.

The immediate release blocker is the confirmed **LLM01** issue.

Files in this skill

  • eval-1.baseline.md1.2 KB
  • eval-1.with-skill.md2.2 KB
  • eval-2.baseline.md1.1 KB
  • eval-2.with-skill.md2 KB
  • eval-3.baseline.md750 B
  • eval-3.with-skill.md2.4 KB
  • eval-4.baseline.md471 B
  • eval-4.with-skill.md716 B
  • eval-5.baseline.md779 B
  • eval-5.with-skill.md1.3 KB
  • trigger-1.md160 B
  • trigger-2.md180 B
  • trigger-3.md162 B
  • trigger-4.md156 B
  • trigger-5.md140 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…