Framework lens
OWASP GenAI / LLM security — documentation support
Line up your agent test pack and controls against OWASP GenAI / LLM and agent-security expectations.
Line up your agent test pack and controls against OWASP GenAI / LLM and agent-security expectations.
Why it matters
OWASP GenAI and LLM guidance names the failure modes agents actually hit — prompt injection, excessive agency, sensitive-information disclosure. It is the natural companion to the test pack: a security-flavoured lens that shows whether the checks and controls that matter for LLM agents are documented and evidenced.
What good looks like
The agent test pack — prompt-injection, jailbreak, data-leakage, tool-boundary, and unapproved-action checks — and its controls, viewed through the OWASP lens as coverage of the named risks, with gaps visible where a relevant check was never run. It reuses the same tests and evidence rather than a parallel checklist.
What can go wrong
The lens is described in offensive-security terms it is not — it is documentation coverage, not an active security probe. A never-run injection check is assumed fine. Excessive-agency risk stays invisible because tool boundaries were never tested or documented.
What AgentProof checks
AgentProof maps documentation and evidence coverage against the OWASP GenAI / LLM risk areas via the one lens engine, pinned to a named framework version and tied to the test pack (a not-run check stays a visible gap). It reports coverage of security expectations and testing evidence — it is not an active security probe and not a security verdict.
Key terms
The exact vocabulary this part of the record uses — grounded in the shipped product model.
- OWASP areas
- prompt-injection, excessive-agency, sensitive-info-disclosure.
- Tied test types
- prompt_injection, jailbreak, data_leakage, tool_boundary, unapproved_action.
- Not-run gap
- A relevant check that was never run stays a visible gap, never a pass.
- Framework version
- The OWASP GenAI / LLM seed is pinned to a named framework version.
Keep reading
Build this record for your own agents
AgentProof turns each part of this into one documented, evidence-backed record — before your compliance review.
Ready to build a compliance-readiness record for your own agent?
Request a compliance readiness pilot to apply this guidance to a real agent.
AgentProof builds a compliance-readiness record, not an official audit, and it does not speak on behalf of any vendor.