-
Notifications
You must be signed in to change notification settings - Fork 49
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Templates for AI LLM VRT Entries #514
Conversation
RRudder
commented
Nov 14, 2023
- Added Prompt Injection template, recommendation, guidance
- LLM Output Handling, Training Data Poisoning, and Excessive Agency/Permission Manipulation are all to be added shortly
* Added Prompt Injection template, recommendation, guidance * LLM Output Handling, Training Data Poisoning, and Excessive Agency/Permission Manipulation are all to be added shortly
* Template, recommendation, and guidance .md files
* Template, Recommendation, Guidance * Grammar fixes for Excessive Agency
These templates cover the AI Application Security issues in bugcrowd/vulnerability-rating-taxonomy#377 |
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
Some updates made to language. There is also some terminology we should rely on more like RBAC
...on/ai_application_security/llm_security/excessive_agency_permission_manipulation/guidance.md
Outdated
Show resolved
Hide resolved
...pplication_security/llm_security/excessive_agency_permission_manipulation/recommendations.md
Outdated
Show resolved
Hide resolved
...pplication_security/llm_security/excessive_agency_permission_manipulation/recommendations.md
Outdated
Show resolved
Hide resolved
...pplication_security/llm_security/excessive_agency_permission_manipulation/recommendations.md
Outdated
Show resolved
Hide resolved
...on/ai_application_security/llm_security/excessive_agency_permission_manipulation/template.md
Outdated
Show resolved
Hide resolved
...on/ai_application_security/llm_security/excessive_agency_permission_manipulation/template.md
Show resolved
Hide resolved
...issions/description/ai_application_security/llm_security/training_data_poisoning/template.md
Outdated
Show resolved
Hide resolved
...on/ai_application_security/llm_security/excessive_agency_permission_manipulation/template.md
Outdated
Show resolved
Hide resolved
submissions/description/ai_application_security/llm_security/prompt_injection/template.md
Outdated
Show resolved
Hide resolved
...issions/description/ai_application_security/llm_security/training_data_poisoning/template.md
Outdated
Show resolved
Hide resolved
…xcessive_agency_permission_manipulation/template.md Co-authored-by: Rami <[email protected]>
…lm_output_handling/recommendations.md Co-authored-by: Rami <[email protected]>
…raining_data_poisoning/template.md Co-authored-by: Rami <[email protected]>
Thank you @drunkrhin0
…rompt_injection/template.md Co-authored-by: Rami <[email protected]>
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
LGTM
There was a problem hiding this comment.
Choose a reason for hiding this comment
The reason will be displayed to describe this comment to others. Learn more.
lgtm