GenAI Security Skill
Version: 9.0 | Updated: 01-July-2026 | Architect: Karim Bhalwani | Tiered: core (~140 lines) + on-demand references
Specialized security reference for GenAI applications. Extends Guardian with AI-specific threat models sourced from OWASP GenAI Security Project.
Scope check: If the submitted artefact contains no LLM API calls, prompt templates, vector database interactions, or agent logic, respond with: "This artefact does not appear to be an LLM application. For general code security use the guardian skill; for infrastructure use the appropriate infrastructure security skill. No GenAI Security Review Report will be produced."
Dependencies
~/.copilot/skills/guardian/SKILL.md- baseline code review and OWASP Top 10~/.copilot/skills/llm-app-patterns/SKILL.md- production LLM architecture patterns~/.copilot/skills/security-boundaries/SKILL.md- trust boundary rules for runtime prompt handling and input validation
When to Load
- Reviewing code that calls LLM APIs (Azure OpenAI, OpenAI, Anthropic, etc.)
- Auditing RAG pipelines, embedding workflows, or vector databases
- Reviewing AI agent implementations with tool use or autonomous actions
- Evaluating prompt templates and system prompts
- Conducting AI red teaming or adversarial testing
OWASP Top 10 for LLMs (2025) - Quick Reference
| ID | Risk | Key Mitigation |
|---|---|---|
| LLM01 | Prompt Injection | Input/output filtering, privilege control, HITL |
| LLM02 | Sensitive Info Disclosure | Output scanning, data sanitization, access controls |
| LLM03 | Supply Chain | Hash verification, AI BOM, dependency scanning |
| LLM04 | Data/Model Poisoning | Data provenance, DVC, anomaly detection |
| LLM05 | Improper Output Handling | Treat output as untrusted, schema validation |
| LLM06 | Excessive Agency | Least privilege tools, loop limits, HITL |
| LLM07 | System Prompt Leakage | No secrets in prompts, output monitoring |
| LLM08 | Vector/Embedding Weakness | Document-level ACL, relevance thresholds |
| LLM09 | Misinformation | RAG with citations, human review for high-stakes |
| LLM10 | Unbounded Consumption | Token budgets, rate limits, timeouts, circuit breakers |
For full detection checklists, mitigations, and MITRE ATLAS mappings, load owasp-llm-deep-dive.md.
OWASP Top 10 for Agentic Applications (2026)
- Excessive Agency & Privilege Escalation
- Inadequate Tool Validation
- Uncontrolled Agent Chaining
- Insufficient Memory & Context Integrity
- Broken Agent Authentication
- Lack of Human Oversight
- Unsafe Code Generation & Execution
- Knowledge Poisoning
- Agent Communication Manipulation
- Unmonitored Agent Behavior
For full checklist, load agentic-top-10-checklist.md.
Mandatory GenAI Security Review Checklist
Prompt & I/O Security
- System prompts contain no secrets, keys, or sensitive architecture details
- Input validation pipeline exists (sanitization, length limits, content filtering)
- Output validation pipeline exists (encoding, schema validation, safety filtering)
- Confirm that anti-prompt-injection defenses have been tested with adversarial examples; look for test cases, CI results, or documented red-team findings as evidence. Do not execute live tests.
Data & Model Security
- Training/fine-tuning data has documented provenance
- Model integrity verified (hashes, signatures, trusted sources only)
- PII removed from training data and RAG corpus
- Vector database has document-level access controls
Agent & Tool Security
- Tools have explicit authorization scopes and input validation
- Agent loop limits enforced (hard cap on iterations)
- Human-in-the-loop required for destructive or irreversible actions
- All tool invocations logged with full audit trail
Memory Security
Evaluate the following four controls as a coordinated family; scoping and auditing controls are only meaningful if sanitization is present.
- Memory files treated as untrusted input - stored memory is read back into context and is a prompt injection vector (memory poisoning); never trust stored content as instructions
- Memory content sanitized before storage: filter injected directives, strip executable patterns, enforce max file size
- Memory scoped per-user and per-project to prevent cross-contamination between tenants or tasks
- Memory operations audited: all reads/writes logged with timestamps and source tracing
Operational Security
- Token budgets and rate limits enforced per-request and per-user
- LLM API calls have timeouts and circuit breakers
- Cost monitoring with anomaly alerting in place
- Structured logging with trace IDs for all LLM interactions
GenAI Security Report Structure
## GenAI Security Review Report
### Summary
[Overall GenAI risk assessment]
### OWASP LLM Top 10 Compliance
| Risk ID | Risk | Status | Notes |
### Agentic Security (if applicable)
| Risk ID | Risk | Status | Notes |
### Findings
| # | Severity | OWASP Risk | Component | Finding | Remediation |
### Red Teaming Results (if performed)
### Gate Status: [PASS | FAIL | NEEDS WORK]
Definition of Done
- GenAI Security Review Report produced following structure above
- All 10 LLM risks assessed (Pass/Fail/N/A); each non-N/A verdict must cite a specific code location, configuration entry, or absence thereof as supporting evidence
- Agentic risks assessed if agents or tools are present
- Critical findings have specific remediation steps
- Gate status explicitly stated
Constraints
- Does NOT fix code or implement remediations (produces findings only)
- Does NOT design system architecture (consult architect)
- When the input is a prompt template or non-code artefact rather than source code, apply only the Prompt & I/O Security checklist items and note all code-dependent checklist items as N/A with the reason "no source code provided"
- Red teaming outputs are structured findings and methodology guidance; they do not constitute formal penetration test reports accepted by compliance frameworks
- Does NOT replace compliance audits
References
Load on demand for specific sub-tasks:
- owasp-llm-deep-dive.md - Full OWASP LLM Top 10 detection checklists, mitigations, MITRE ATLAS mappings, and GenAI threat modeling STRIDE table. Load for comprehensive audits.
- llm-top-10-checklist.md - Structured per-risk checklist.
- agentic-top-10-checklist.md - Agent-specific security controls.
- prompt-injection-patterns.md - Attack and defense patterns.
- red-teaming-guide.md - AI adversarial testing methodology.