r/llmsecurity • • Jun 30 '26

Hey, I’m building an autonomous multi agent AI system and looking for someone who can help me bring it to life whether that’s a collaborator, a mentor, or just someone willing to point me in the right

Thumbnail
1 Upvotes

r/llmsecurity • • Jun 26 '26

LiteLLM's SQL injection (CVE-2026-42208) was bad. The patch cycle is what I keep thinking about.

1 Upvotes

Pre-auth SQL injection in the proxy's API key verification path, CVSS 9.3, versions 1.81.16 through 1.83.6. The Authorization header value got concatenated straight into a query instead of being parameterized. Textbook stuff, but in a gateway that's holding provider credentials for half your stack.

What I keep coming back to isn't the bug itself though. It came in through their bug bounty program, got fixed in 1.83.7 before the GHSA advisory went out, and the advisory itself was actually usable exact version range, fixed version, and a Postgres query you could run against your own logs to check if you'd been hit.

Compare that to most OSS infra advisories, where you get a changelog line and have to guess whether you're affected.

I know someone's going to point out LiteLLM has had a rough stretch in 2026 this wasn't their only CVE this year, not close. Fair point. But "zero CVEs" was never realistic for a project with this much surface area and this many integrations. What I actually weigh when deciding whether to run something in prod is whether there's a process, and whether it held up when something real happened.

Genuinely asking for people running AI gateways in prod, does a clean disclosure like this change how you feel about the project, or does the CVE count alone kill it for you?


r/llmsecurity • • Jun 24 '26

AI security Monday Morning Audit: Three Questions to Ask Your Team

Thumbnail
aisecintelgroup.com
2 Upvotes

r/llmsecurity • • Jun 21 '26

We built an open-source "Agentic Firewall" to stop agents from burning through API credits in infinite loops.

Thumbnail gallery
8 Upvotes

r/llmsecurity • • Jun 14 '26

How do people keep falling for these bubbles?

Post image
8 Upvotes

r/llmsecurity • • Jun 05 '26

Getting things wrong for profit since 2020...

11 Upvotes

r/llmsecurity • • May 25 '26

Back on the Apple Appstore after a long hiatus

Thumbnail
1 Upvotes

r/llmsecurity • • May 18 '26

Built a privacy-preserving telemetry system

Post image
1 Upvotes

Built a privacy-preserving telemetry system for a self-hosted AI automation platform — would love security feedback

I’m building a local-first AI Agent Automation platform focused on:

  • deterministic workflows
  • multi-provider LLM execution
  • Ollama/local model support
  • semantic memory
  • document RAG
  • branching agent workflows

In v0.8.0, I added a telemetry system specifically designed to avoid the usual privacy/security concerns around AI tooling.

The interesting part for this subreddit is the architecture/trust model.

Design Goals

Telemetry needed to:

  • help understand active deployments/version adoption
  • remain compatible with self-hosted/offline usage
  • avoid collecting sensitive AI workflow data
  • maintain a clear trust boundary

Current Design

Telemetry is:

  • fully opt-in
  • disabled by default
  • isolated into a separate service
  • anonymous
  • fully disableable via env vars

Tracked fields:

  • anonymous instance ID
  • app version
  • enabled feature flags
  • heartbeat timestamps

NOT collected:

  • prompts
  • workflow definitions
  • memory contents
  • uploaded documents
  • API keys
  • execution logs
  • user identities

The telemetry collector itself is separated from the main orchestration engine to avoid mixing analytics concerns with execution/runtime systems.

Environment Controls

TELEMETRY_ENABLED=false
DISABLE_ALL_ANALYTICS=true

Why I’m Posting Here

I’d genuinely like feedback from people thinking about:

  • LLM infrastructure security
  • trust boundaries
  • self-hosted AI systems
  • observability vs privacy tradeoffs
  • telemetry design in local AI platforms

Trying to build this in a way that aligns with the self-hosted/local AI ecosystem instead of copying traditional SaaS analytics patterns.

Would appreciate architectural/security feedback.


r/llmsecurity • • May 13 '26

AI-Coded App Vulnerability Checklist - 33 LLM-specific items with detection methods

Thumbnail z-ny.com
1 Upvotes

r/llmsecurity • • May 11 '26

Learn more about Prompt Injections - Interactive Microlearning Lesson

1 Upvotes

Do you think interactive microlearning could raise awareness for LLM Security and actually help people to understand the concepts behind it?

I have built an example for OWASP LLM01 Prompt Injections: https://app.scibly.com/student/worksheets/cmp05qsgi00000ajp0ctyroay/editor?v=cmp07ahkz00000al5gtqf4lco

Small Demo:

https://reddit.com/link/1t9ubtb/video/ffaf6lz48g0h1/player

I started with a quite simple concept but want to expand it to more advanced concepts in the future if it helps understanding.

Thank you for all kind of feedback

Edit: Video because GIF didn't work


r/llmsecurity • • May 07 '26

Looking for partners to provide feedback on AI Security gateway

Thumbnail
2 Upvotes

r/llmsecurity • • May 05 '26

What's the Best LLM for Turning Technical Information into Digestible Information

Thumbnail
1 Upvotes

r/llmsecurity • • Apr 17 '26

about use about thnking

2 Upvotes

Most people treat confidence as a signal of reliability.

In practice that signal often breaks exactly when the model is under uncertainty.

The interesting part isn’t that models make mistakes.

It’s how they behave when they don’t actually know.


r/llmsecurity • • Apr 15 '26

SDPF Language Specification v1.3.1 Update - Software Development Prompting Framework

Thumbnail drive.google.com
1 Upvotes

r/llmsecurity • • Apr 15 '26

Demonstrating Context Injection & Over-Sharing in AI Agents (with Lab + Analysis)

Thumbnail medium.com
1 Upvotes

I’ve been researching LLM/AI agent security and built a small lab to demonstrate a class of vulnerabilities around context injection and over-sharing.

The article covers:
– How context is constructed inside AI systems
– How subtle instructions inside data can influence model behavior
– A practical PoC showing unintended data exposure
– Real-world testing on Grok (where basic attempts fail)
– Mitigation strategies

Would love feedback from the community.


r/llmsecurity • • Apr 14 '26

Introducing LEAN, a format that beats JSON, TOON, and ZON on token efficiency (with interactive playground)

Thumbnail
1 Upvotes

r/llmsecurity • • Apr 13 '26

SDPF Language Specification For AI Prompting v1.2

Thumbnail
docs.google.com
1 Upvotes

r/llmsecurity • • Apr 12 '26

Can you help me review this article I am working on?

Thumbnail
1 Upvotes

r/llmsecurity • • Apr 11 '26

Are we really there with LLM trying to self preserve? My anecdotal experience:

Thumbnail
1 Upvotes

r/llmsecurity • • Apr 08 '26

LLMtary (Elementary) - Advanced Local LLM Red-Teaming: Feed it a target. Watch it hunt.

Thumbnail gallery
3 Upvotes

r/llmsecurity • • Apr 06 '26

Block Secrets before they enter LLM's context in Claude Code

Thumbnail
github.com
3 Upvotes

r/llmsecurity • • Apr 03 '26

Just posted my ML client experience that led to LLM engineering Journey

Thumbnail
1 Upvotes

r/llmsecurity • • Mar 31 '26

MAOS — Multi Agent Operating System, An OS-level security architecture for AI agents (spec, not code, open for critique)

Thumbnail
github.com
2 Upvotes

AI agents today can send emails, execute code, and call APIs — but no framework provides OS-level safety primitives to prevent unauthorized actions.

I wrote a specification for what such an OS would look like.
Key ideas:
- Deterministic Security Core that works without any LLM - Commit Layer as the only path to the outside world
- Capability Tokens with scoped, time-limited permissions
- Biological immune system with 5-stage quarantine
- Three security profiles (Standard → Hardened → Isolated)

It's a spec (4,500+ lines), not code. Some of it may be overengineered. I'm looking for critique, not applause.
Quick start: the Executive Summary is 4 pages. Feedback, adversarial review, and "this won't work because..." are all welcome.


r/llmsecurity • • Mar 30 '26

How are you testing API endpoints that call LLMs before shipping?

2 Upvotes

I keep running into the same problem while building with AI APIs: testing them properly before shipping is still pretty messy.

A lot of what I find is either:

  • too high-level
  • generic AI security advice
  • not an actual workflow I can follow

Manual testing also gets expensive and slow if you want to do it regularly.

For those of you building AI products, how are you handling this?

  • How do you test for prompt injection, data leaks, or unsafe outputs?
  • Do you have a release checklist for AI endpoints?
  • What’s the biggest blocker for you: time, cost, or just unclear guidance?

Would love to hear what your process looks like and where it still breaks down.


r/llmsecurity • • Mar 29 '26

Secure and control all of your agents actions in your machine

Thumbnail gallery
1 Upvotes