vulns.co
/
GKData.io MCP

OWASP Cheat Sheet Series · 1 min read

LLM Prompt Injection Prevention Cheat Sheet

Defense-in-depth guidance for LLM applications that consume untrusted content or invoke tools. Covers data provenance, least privilege, action authorization, monitoring, and the limitations of guardrails.

Open the reference Architecture GuideReviewed 2026-10-02

How to use this reference

Review permissions and action boundaries around an owned AI integration; treat filters and model-based checks as partial defenses rather than guarantees.

Before reading

  • LLM application and tool-call basics
  • Trust boundaries
  • An understanding of the application's data and permissions

Context and limits

  • Includes attack examples; this collection uses it as a defensive-design reference
  • Guidance evolves and individual examples require contextual evaluation

Related visual models

Sources and provenance

  1. LLM Prompt Injection Prevention Cheat Sheet OWASP Cheat Sheet Series · reviewed 2026-10-02

Record reviewed 2026-10-02. Snapshot 53796974ace8. Open the complete JSON contract.

GitHub snapshot 2026-10-04

53796974ace8 · JSON exports & schemas · CC BY 4.0 content / MIT software