All repositories

SecurityOWASP

www-project-top-10-for-large-language-model-applications

The archive of the OWASP Top 10 for LLM Applications: the ten main risks with descriptions and mitigations. The current 2026 release has moved to the GenAI Security Project repository.

Who it is for

For developers and security people who want to check against the industry list of LLM risks.

How to start

  1. Read the notice at the top of the README: the current version moved to GenAI-Security-Project/GenAI-LLM-Top10
  2. Open the OWASP GenAI LLM Top 10 2026 release at genai.owasp.org
  3. Check your project against each of the ten risks

Steps are taken from the README. Check the current version in the repository before running them.

Stars over the last 30 days

+49Sep 6 — Oct 5
1,3851,434

Author's description

OWASP Top 10 for Large Language Model Apps (Part of the GenAI Security Project)

data-privacy-stack

presidio

A framework that finds and masks personal data in text, images and tables. It detects the data, then redacts or replaces it so it can be safely sent to a model.

11Kstars+430 in 30 dPython

NVIDIA

garak

A vulnerability scanner for LLMs: it runs a model through a set of probes for prompt injection, data leakage, toxicity and other failures. Works as a command-line tool.

9.4Kstars+325 in 30 dPython

guardrails-ai

guardrails

A Python framework that checks LLM inputs and outputs with ready validators from Guardrails Hub and helps produce structured answers. It catches risks before a reply reaches the user.

7.5Kstars+137 in 30 dPython

NVIDIA-NeMo

Guardrails

NVIDIA's toolkit for programmable rails in LLM-based conversational systems. Rules live in config and control what the bot talks about and does.

7.2Kstars+183 in 30 dPython

microsoft

PyRIT

Microsoft's framework for proactively finding risks in generative AI systems. It helps automate red teaming against models and applications.

4.6Kstars+174 in 30 dPython

meta-llama

PurpleLlama

Meta's generative AI safety project: the Llama Guard and Prompt Guard filter models, the Code Shield scanner and the CyberSec Eval test suites. It pairs defense with attack-based testing.

4.4Kstars+45 in 30 dPython