Skip to content

OWASP 覆盖矩阵

本页由 pnpm gen:coverage 从规则的 threats 元数据与评测用例生成,不手工维护。 名录版本 2026.08.0(OWASP LLM Top 10 2026 · Agentic/ASI Top 10 2026)。 「攻击用例验证」列出内置数据集中真实打到该威胁的攻击用例——声称覆盖与验证过覆盖是两回事。

OWASP LLM 应用 Top 10(2026)

威胁名称防护规则攻击用例验证
LLM01:2026提示词注入input-hygiene
injection.block (概率层)
injection.defang (概率层)
spotlight.delimit (概率层)
lethal-trifecta
inj-override-zh
inj-override-en
inj-persona-hijack
inj-unicode-tag
inj-zero-width
inj-control-chars
inj-tool-result
inj-forged-freeze-mark
exp-novel-phrasing
exf-lethal-trifecta
LLM02:2026敏感信息泄露lethal-trifecta
pii.redact
row-filter
field-mask
exf-lethal-trifecta
out-pii-leak
dat-row-exfil
LLM03:2026过度代理rbac-tool-gate
approval-gate
dat-no-identity
dat-unknown-role
dat-tool-escape
dat-big-refund
dat-missing-amount
LLM04:2026供应链——未覆盖
LLM05:2026数据与模型投毒——未覆盖
LLM06:2026无界消耗max-length
output-caps
inj-flood
LLM07:2026虚假信息citation-faithfulness
numeric-trace
out-ungrounded-number
out-userstated-commit
out-fake-citation
out-refusal-smuggle
LLM08:2026隐藏上下文暴露——未覆盖
LLM09:2026向量与嵌入弱点citation-faithfulnessout-fake-citation
LLM10:2026输出处理不当link-policyexf-output-link

OWASP Agentic 应用 Top 10(2026)

威胁名称防护规则攻击用例验证
ASI01:2026代理目标劫持injection.block (概率层)
injection.defang (概率层)
inj-override-zh
inj-override-en
inj-persona-hijack
ASI02:2026工具滥用与利用lethal-trifecta
link-policy
rbac-tool-gate
approval-gate
exf-lethal-trifecta
exf-output-link
dat-tool-escape
dat-big-refund
ASI03:2026身份与权限滥用rbac-tool-gatedat-no-identity
dat-unknown-role
dat-tool-escape
ASI04:2026代理供应链漏洞——未覆盖
ASI05:2026意外代码执行——未覆盖
ASI06:2026记忆与上下文投毒spotlight.delimit (概率层)inj-tool-result
inj-forged-freeze-mark
ASI07:2026不安全的代理间通信——未覆盖
ASI08:2026级联故障——未覆盖
ASI09:2026人-代理信任利用——未覆盖
ASI10:2026失控代理——未覆盖

未覆盖:LLM04:2026、LLM05:2026、LLM08:2026、ASI04:2026、ASI05:2026、ASI07:2026、ASI08:2026、ASI09:2026、ASI10:2026。空格是事实,不是遗漏——按需自写规则或等后续里程碑。