REPOGEO 报告 · LITE
OWASP/www-project-top-10-for-large-language-model-applications
默认分支 main · commit 02059576 · 扫描时间 2026/5/17 05:11:15
星标 1,250 · Fork 312
下方为分数趋势(含全部就绪扫描;左旧右新,可横向滚动)。表格明细默认折叠,展开后每页 10 条,最新在上。
共 2 条就绪扫描。点击下方按钮展开表格(每页 10 条,可翻页)。
行动计划告诉你下一步要做什么——按影响力排序、可直接复制粘贴的修改。品类可见性是真正的 GEO 测试:当用户向 AI 提一个不带品牌、本应让 OWASP/www-project-top-10-for-large-language-model-applications 浮出水面的问题时,AI 是真的推荐了你,还是推荐了你的竞品?客观检查验证 AI 引擎最先权衡的那些元数据信号。自指检查判断 AI 是否还认识你的名字。
行动计划 — 可复制粘贴的修复
3 条由 gemini-2.5-flash 生成、按优先级排序的修改。修完后请把对应条目标记为完成。
- highreadme#1Clarify the project's nature as a security guideline in the README's opening
原因:
当前The core definition 'The OWASP Top 10 for Large Language Model Applications is a standard awareness document...' appears under '## Overview and Audience 🗣️'.
复制粘贴的修复# OWASP Top 10 for Large Language Model Applications The OWASP Top 10 for Large Language Model Applications is a standard awareness document for developers and web application security. It represents a broad consensus about the most critical security risks to Large Language Model (LLM) applications. This repository contains the official content for this project, which is housed under the comprehensive **OWASP GenAI Security Project**. Visit our main project site: genai.owasp.org
- mediumtopics#2Add more specific topics to improve categorization
原因:
当前ai, appsec, llm, llm-security
复制粘贴的修复ai, appsec, llm, llm-security, ai-security-guidelines, llm-security-standards, generative-ai-risk, security-best-practices
- lowlicense#3Clarify the project's license directly in the README
原因:
复制粘贴的修复## License This project is licensed under the Creative Commons Attribution-ShareAlike 4.0 International License (CC BY-SA 4.0). For details, see the [LICENSE](LICENSE) file.
本次扫描解析到的品类 GEO 通道:google/gemini-2.5-flash, deepseek/deepseek-v4-flash
品类可见性 — 真正的 GEO 测试
向 google/gemini-2.5-flash 提出的不带品牌问题。AI 推荐了你,还是推荐了别人?
各模型使用同一组问题 — 切换标签对比回答与排名。
- AWS API Gateway · 被推荐 2 次
- Azure API Management · 被推荐 2 次
- NVIDIA/NeMo-Guardrails · 被推荐 1 次
- microsoft/presidio · 被推荐 1 次
- Lakera Guard · 被推荐 1 次
- 品类问题What are the most critical security vulnerabilities when building large language model applications?你:未被推荐AI 推荐顺序:
- NeMo Guardrails (NVIDIA/NeMo-Guardrails)
- Presidio (microsoft/presidio)
- Lakera Guard
- Microsoft Purview DLP
- Google Cloud DLP
- Symantec DLP
- OAuth 2.0
- OpenID Connect
- AWS API Gateway
- Azure API Management
- Kong Gateway (Kong/kong)
- Cloudflare
- NGINX (nginx/nginx)
- AWS API Gateway
- Azure API Management
- Snyk
- OWASP Dependency-Check (jeremylong/DependencyCheck)
- Black Duck
- OpenAI
- Anthropic
- Hugging Face Hub
- Aqua Security
- Twistlock
AI 推荐了 24 个替代方案,却始终没点名 OWASP/www-project-top-10-for-large-language-model-applications。这就是要补上的差距。
查看 AI 完整回答
- 品类问题Where can I find best practices for securing generative AI applications against common threats?你:未被推荐AI 推荐顺序:
- OWASP Top 10 for Large Language Model Applications (LLM Top 10)
- NIST AI Risk Management Framework (AI RMF)
- Microsoft Azure AI Security Best Practices
- Google Cloud AI Security Best Practices
- Hugging Face Security Best Practices
- MITRE ATLAS (Adversarial Threat Landscape for Artificial-Intelligence Systems)
AI 推荐了 6 个替代方案,却始终没点名 OWASP/www-project-top-10-for-large-language-model-applications。这就是要补上的差距。
查看 AI 完整回答
客观检查
针对 AI 引擎最看重的元数据信号的规则审计。
- Metadata completenesspass
- README presencepass
自指检查
当被直接问到你时,AI 是否还知道你的仓库存在?
- Compared to common alternatives in this category, what is the core differentiator of OWASP/www-project-top-10-for-large-language-model-applications?passAI 未点名 OWASP/www-project-top-10-for-large-language-model-applications —— 很可能在说另一个项目
AI 的回答可能信誓旦旦却是错的。请按事实核对:技术栈、目标人群、差异化点是不是和你实际的对得上?
- If a team adopts OWASP/www-project-top-10-for-large-language-model-applications in production, what risks or prerequisites should they evaluate first?passAI 未点名 OWASP/www-project-top-10-for-large-language-model-applications —— 很可能在说另一个项目
AI 的回答可能信誓旦旦却是错的。请按事实核对:技术栈、目标人群、差异化点是不是和你实际的对得上?
- In one sentence, what problem does the repo OWASP/www-project-top-10-for-large-language-model-applications solve, and who is the primary audience?passAI 未点名 OWASP/www-project-top-10-for-large-language-model-applications —— 很可能在说另一个项目
AI 的回答可能信誓旦旦却是错的。请按事实核对:技术栈、目标人群、差异化点是不是和你实际的对得上?
嵌入你的 GEO 徽章
把这个徽章贴进 OWASP/www-project-top-10-for-large-language-model-applications 的 README。每次重新扫描都会自动更新,并跳到最新报告——是「我在乎 AI 可发现性」最简单的公开证明。
[](https://repogeo.com/zh/r/OWASP/www-project-top-10-for-large-language-model-applications)<a href="https://repogeo.com/zh/r/OWASP/www-project-top-10-for-large-language-model-applications"><img src="https://repogeo.com/badge/OWASP/www-project-top-10-for-large-language-model-applications.svg" alt="RepoGEO" /></a>订阅 Pro,解锁深度诊断
OWASP/www-project-top-10-for-large-language-model-applications — 轻量扫描仍免费;本卡列出 Pro 相对轻量的深度额度。
- 深度报告每月 10 次
- 无品牌品类查询5,轻量 2
- 优先行动项8,轻量 3