LLM07 · OWASP LLM Top 10

System Prompt Leakage (LLM07)

An attacker extracts the system prompt or other privileged context from an LLM. The prompt may contain business logic, internal documentation, or even credentials.

Rank
LLM07 of 10
In the check
Not cited directly by a question
LLM01
Prompt Injection
LLM02
Sensitive Information Disclosure
LLM03
Supply Chain
LLM04
Data and Model Poisoning
LLM05
Improper Output Handling
LLM06
Excessive Agency
LLM07
System Prompt Leakage
LLM08
Vector and Embedding Weaknesses
LLM09
Misinformation
LLM10
Unbounded Consumption
Figure 1. The OWASP LLM Top 10, with LLM07 marked.
In practice

What it looks like in practice

Three shapes this risk takes in real deployments.

Example 1

A user asks the chatbot to 'repeat your instructions' and receives the full system prompt.

Example 2

Prompt-injection extracts an embedded API key.

Example 3

A jailbreak surfaces internal pricing logic the company considers confidential.

Controls

Controls that close it

The controls the check looks for when this entry applies.

Don't put secrets in prompts

Don't put business logic that competitors could extract

Output filtering for prompt-leakage patterns

Monitor for known prompt-leakage attack signatures

Posture Check

Where the check cites it

The AI Posture Check cites OWASP LLM Top 10, including this entry, when placing you at Crawl, Walk, Run or Sprint.

The questions cite the control frameworks a regulator would expect you to hold: NIST AI RMF, ISO 42001 and the OWASP LLM Top 10. Your stage on the check is a starting point for an EU AI Act conformity review, not a substitute for one.

Ready when you are

Score yourself against this framework.

Five questions, each citing its source. You get your stage, your place on the chart and the one move that matters next.

  • A few minutes for most people
  • Free, from CWS
  • Your stage, the chart and the next move, by email or live with an engineer