| name | llm-app-security |
| description | Secure LLM-powered applications with input validation, output controls, tenant isolation, and abuse prevention. |
| license | MIT |
| metadata | {"author":"devops-skills","version":"1.0"} |
LLM Application Security
Harden chatbots and AI features embedded in web and mobile products.
Baseline Security Checklist
- Validate and classify all user-provided context.
- Separate system prompts from user content strictly.
- Add moderation for toxic, harmful, and policy-violating outputs.
- Enforce tenant boundaries in retrieval and memory layers.
- Rate-limit high-cost endpoints.
Secure RAG Pattern
- Ingest content with malware and secret scanning.
- Tag documents by tenant and access policy.
- Filter retrieval candidates by user authorization.
- Add provenance metadata in final responses.
Related Skills