Skip to Main Content
AI / LLM Security Testing Checklist Back to Top

AI / LLM Security Testing Checklist

By shadowe1ite
5 minutes

A working checklist for testing an LLM-backed application end to end. It’s the AI Hacking 101 notes squeezed into “did I actually do this?” form — tick-boxes grouped by phase, from scoping through to writing it up.

Only run this against a target you have written authorization for, inside an agreed scope. Several sections (agentic tools, ticket close/escalate, load testing) change state or cost money — get explicit sign-off before you touch them.

  • LLMmap — minimal-query model fingerprinting (“nmap for LLMs”).
  • P4RS3LT0NGV3 — encoding/obfuscation + prompt-mutation workbench.
  • Burp Suite — inspect the chat API and its response metadata.
  • Small scripts for determinism and rate-limit probing.

0. Scope & rules of engagement

1. Threat model the app first

2. Recon & fingerprinting

Model & behavior

Retrieval & prompt

Infrastructure

The system prompt is not a security control. Treat anything you extract from it (URLs, emails, key formats, org IDs) as a lead to chase, not as the finding itself.

3. Prompt injection

Direct injection

Indirect injection

Indirect injection rides in as “trusted” business data, so it isn’t scrutinized like something typed into the chat box — it’s usually far more effective than a direct prompt, and it’s the path a real attacker takes.

Multi-turn injection

Obfuscation & encoding

4. Jailbreaks

5. Harmful & off-topic output

6. RAG / retrieval abuse

Treat any partial hit as a foothold. Even a sliver of useful info is worth keeping — note what came back and how you asked, then reshape the next prompt to dig down that same path.

7. Access control & excessive agency

These tests change state. Only run close / escalate / delete against test data you’re explicitly cleared to touch, and confirm nothing persists to real users.

8. Map findings to a framework

Buy Me a Coffee if you liked this one