Reference / Glossary
AI and offensive security glossary.
The words we use in scopes, reports and research, defined the way we use them. Each entry answers first, names the framework id where one exists, and links its source. Two layers, model and stack, plus the process and standards that hold a test together.
53Terms defined
- Model layer
- 24
- Stack layer
- 12
- Process and standards
- 17
All terms
A
- Agent goal hijack
Redirecting an agent away from the goal its user or developer gave it, usually through content it reads, so it pursues another goal with the user's permissions. It is ASI01 in the OWASP Top 10 for Agentic Applications (2026).
See alsoAI agent, Indirect prompt injectionSourceOWASP Top 10 for Agentic Applications 2026
- AI agent
An AI system that pursues a goal over several steps by choosing and calling tools, such as reading mail, querying an API or writing a file. Acting on someone's behalf is what makes it useful, and what makes everything it reads a security boundary.
See alsoExcessive agency, Agent goal hijack, Model Context Protocol (MCP)
- AI red teaming
Authorized adversarial testing of an AI system. Testers attack the model, its prompts, its data sources and its tools the way a real attacker would, to find exploitable failures before customers or attackers do.
See alsoLLM penetration test, Prompt injection
- Attack surface
Everything an attacker can reach and influence: endpoints, accounts, integrations and, for AI features, every source of text the model reads.
See alsoScope
- Attestation letter
A one-page letter stating the scope, dates and outcome of a test, so you can show a customer or an auditor that it happened without sharing the findings.
- Authorization letter (vrijwaringsverklaring)
The written permission from a system's owner that makes a test lawful. Without it, a penetration test is an attack. For anything a vendor hosts, the vendor's permission is needed as well.
See alsoRules of engagement
B
- Black box testing
Testing with no inside knowledge, the way an outside attacker starts: no source code, no architecture notes, often no account.
See alsoGrey box testing, White box testing
- Broken function level authorization
An API letting a caller use a function their role should not reach, such as an administrative action called with a normal user's account. It is API5 in the OWASP API Security Top 10 (2023).
See alsoBroken object level authorization (BOLA)SourceOWASP API Security Top 10 2023
- Broken object level authorization (BOLA)
An API returning or changing an object, such as an invoice or a claim, without checking that the caller may access that specific object. It is API1 in the OWASP API Security Top 10 (2023).
See alsoTenant isolation, Broken function level authorizationSourceOWASP API Security Top 10 2023
- Business logic flaw
A flaw in how an application's rules work rather than in its code's syntax: skipping a payment step, applying a discount twice, approving your own request. Scanners do not know your rules, so these need a person. The OWASP Web Security Testing Guide tests them as a category of its own.
See alsoPenetration test (pentest)SourceOWASP Web Security Testing Guide 4.2
C
- Coordinated vulnerability disclosure (CVD)
Reporting a vulnerability privately to whoever can fix it, and publishing only after a fix or an agreed deadline. Ours is on the disclosure policy page.
See alsosecurity.txt
- Cross-layer finding
A finding that starts in one layer and ends in the other: a prompt injection that reaches an API without authorization checks, or a tool call that reads another tenant's data. Our reports list these paths separately, because neither a model test nor a stack test alone would find them.
See alsoImproper output handling, Tenant isolation
- CVSS v4.0
Version 4.0 of the Common Vulnerability Scoring System, maintained by FIRST: a standard way to rate a vulnerability's severity from its exploitability and impact, as a score from 0.0 to 10.0.
See alsoFindingSourceFIRST, CVSS v4.0 specification
D
- Data and model poisoning
Manipulating the data a model is trained, fine-tuned or grounded on, or a pre-trained component it is built from, to plant weaknesses, bias or hidden behaviour. It is LLM05 in the OWASP 2026 list, and the EU AI Act names data poisoning and model poisoning among the attacks high-risk systems must resist.
See alsoRAG poisoning, EU AI ActSourceOWASP Top 10 for LLM Applications 2026, AI Act Art. 15(5)
- Denial of wallet
An attack that inflates an AI application's usage costs until the invoice, rather than the server, becomes the outage. OWASP covers it under LLM06:2026 Unbounded Consumption; MITRE ATLAS calls the technique cost harvesting.
See alsoUnbounded consumptionSourceOWASP Top 10 for LLM Applications 2026, MITRE ATLAS
E
- EU AI Act
Regulation (EU) 2024/1689, the EU law on artificial intelligence. Its Article 15 asks high-risk AI systems for accuracy, robustness and cybersecurity, from 2 December 2027 for Annex III systems. More on our Article 15 page.
See alsoNIS2, Data and model poisoningSourceAI Act Art. 15, AI Omnibus, Art. 113(c)
- Excessive agency
The risk that an LLM-based system takes damaging actions because it has more tools, permissions or autonomy than its task needs. It is LLM03 in the OWASP Top 10 for LLM Applications 2026.
See alsoAI agent, Tool misuseSourceOWASP Top 10 for LLM Applications 2026
F
- Finding
One confirmed security issue in a report: what it is, where it is, what an attacker could do with it, how severe it is, and how to fix it.
See alsoCVSS v4.0, Retest, Reproduction rate
G
- Grey box testing
Testing with partial knowledge: typically an account for each role, API documentation and, for AI features, the system prompt and tool definitions. It gives the most coverage per testing day.
See alsoBlack box testing, White box testing
- Guardrail
A control that filters or constrains what goes into or comes out of a model: input classifiers, output filters, policy prompts. Useful, and never a substitute for testing, because a guardrail is itself something an attacker probes.
See alsoJailbreak, AI red teaming
H
I
- Identity and privilege abuse
An agent acting with credentials or permissions broader than its task, or borrowing a user's identity in a way someone else can exploit. It is ASI03 in the OWASP Top 10 for Agentic Applications (2026).
See alsoExcessive agency, Tenant isolationSourceOWASP Top 10 for Agentic Applications 2026
- Improper output handling
Passing model output to other systems without validating it, so text from the model can become script in a browser, a query in a database or a command on a server. It is LLM10 in the OWASP 2026 list.
See alsoCross-layer findingSourceOWASP Top 10 for LLM Applications 2026
- Indirect prompt injection
Prompt injection delivered through content the model retrieves or processes, such as a web page, a RAG passage, an email or a tool result, instead of through the chat box. The attacker never has to talk to the system, which is why it matters most for agents.
See alsoPrompt injection, RAG poisoningSourceMITRE ATLAS
J
- Jailbreak
An attempt to make a model ignore its safety training. Prompt injection targets the application's instructions instead. MITRE ATLAS lists LLM jailbreak as its own technique.
See alsoPrompt injection, GuardrailSourceMITRE ATLAS
L
- LLM penetration test
A scoped, time-boxed security assessment of an application built on a large language model. It covers the model's inputs and outputs and everything the model can reach: retrieval sources, tools, APIs, user data and other tenants.
See alsoAI red teaming, Penetration test (pentest)
M
- Memory and context poisoning
Planting content in an agent's memory or conversation context so that it shapes later decisions, for the same user or for others. It is ASI06 in the OWASP Top 10 for Agentic Applications (2026).
See alsoRAG poisoning, AI agentSourceOWASP Top 10 for Agentic Applications 2026
- MITRE ATLAS
MITRE's knowledge base of adversary tactics and techniques against AI systems, with ids such as AML.T0051 for LLM prompt injection. We map AI findings to it alongside the OWASP lists.
See alsoOWASP Top 10 for LLM ApplicationsSourceMITRE ATLAS
- Model Context Protocol (MCP)
An open-source standard for connecting AI applications to external systems: data sources, tools and workflows. An MCP server exposes tools; an agent that connects to it trusts their descriptions and their results.
See alsoTool poisoning, AI agentSourcemodelcontextprotocol.io
N
- NIS2
The EU directive on a high common level of cybersecurity, Directive (EU) 2022/2555. Its Dutch implementation, the Cyberbeveiligingswet, has applied since 15 August 2026. More on our NIS2 page.
See alsoEU AI ActSourceNIS2 Directive, OJ L 333, Staatsblad 2026, 189
O
- OWASP API Security Top 10
OWASP's list of the ten most critical API security risks. The current edition is from 2023 and starts with broken object level authorization, API1:2023.
See alsoBroken object level authorization (BOLA), OWASP Web Security Testing Guide (WSTG)SourceOWASP API Security Top 10 2023
- OWASP Top 10 for Agentic Applications
OWASP's list of the ten most critical risks for AI agents, with ids ASI01 to ASI10, published in December 2025 as the 2026 edition.
See alsoAgent goal hijack, Tool misuseSourceOWASP GenAI
- OWASP Top 10 for LLM Applications
OWASP's list of the ten most critical risks for applications built on large language models, with ids LLM01 to LLM10. The 2026 edition was published in August 2026, with prompt injection first.
See alsoPrompt injection, OWASP Top 10 for Agentic ApplicationsSourceOWASP GenAI
- OWASP Web Security Testing Guide (WSTG)
OWASP's guide to testing the security of web applications, organised in 12 categories such as authorization (WSTG-ATHZ) and business logic (WSTG-BUSL). We map stack findings to it.
See alsoOWASP API Security Top 10, Business logic flawSourceOWASP Web Security Testing Guide 4.2, OWASP WSTG
P
- Penetration test (pentest)
An authorized, simulated attack by security specialists that proves which vulnerabilities are actually exploitable, followed by a report with evidence, risk ratings and concrete fixes.
See alsoVulnerability scan, Scope
- Prompt injection
An attack in which text processed by a large language model, typed by a user or hidden in a document, email or web page, overrides the developer's instructions. OWASP ranks it first in its Top 10 for LLM Applications 2026.
See alsoIndirect prompt injection, JailbreakSourceOWASP Top 10 for LLM Applications 2026
R
- RAG poisoning
Planting malicious or misleading content in the documents a RAG system searches, so the model repeats it as fact or follows instructions hidden inside it. MITRE ATLAS lists it as a technique.
See alsoRetrieval-augmented generation (RAG), Indirect prompt injection, Data and model poisoningSourceMITRE ATLAS
- Regression pack
Each confirmed finding turned into a test you can rerun: an HTTP request collection for stack findings; prompt sets, injected documents and tool-call traces for AI findings. It turns a one-off test into a check for the next release.
See alsoRetest
- Reproduction rate
How often a finding reproduces across repeated attempts, reported as n of 10 with the model and its settings recorded. Models are probabilistic, so one successful attempt is an anecdote and 7 of 10 is a measurement.
See alsoFinding
- Retest
Testing a finding again after it was fixed, to confirm that the fix works and did not open something else. The result goes into the report as the finding's status.
See alsoRegression pack, Finding
- Retrieval-augmented generation (RAG)
A design in which an AI application searches a document store for passages relevant to a question and hands them to the model as context. Everything in that store can steer the answer, so the store is part of the attack surface.
- Rules of engagement
The written agreement on how a test runs: the window, rate limits, contacts on both sides, what is off limits, and how one message stops all testing. Ours are on the rules of engagement page.
S
- Scope
The systems, accounts, environments and time window a test covers, agreed in writing before it starts. What is out of scope is written down too, so the report's blind spots are on record.
See alsoRules of engagement, Attack surface
- security.txt
A text file at
/.well-known/security.txtthat tells researchers where to report a vulnerability and which policy applies. RFC 9116 defines it, and requires an Expires date so stale contacts age out. Ours is live.See alsoCoordinated vulnerability disclosure (CVD)SourceRFC 9116
- Sensitive information disclosure
An AI application revealing data it should not, such as personal data, credentials, another customer's records or confidential business data, through its answers or its actions. It is LLM02 in the OWASP Top 10 for LLM Applications 2026.
See alsoTenant isolation, Vector and embedding weaknessesSourceOWASP Top 10 for LLM Applications 2026
- Server-side request forgery (SSRF)
Making a server send requests to a destination of the attacker's choosing, often internal systems or a cloud metadata service the attacker cannot reach directly. It is API7 in the OWASP API Security Top 10 (2023).
See alsoCross-layer findingSourceOWASP API Security Top 10 2023
T
- Tenant isolation
In a multi-tenant SaaS product, the guarantee that one customer can never read or change another's data. It is enforced in many places at once, from API authorization to storage and AI retrieval, so it is tested end to end.
See alsoBroken object level authorization (BOLA), Vector and embedding weaknesses
- Tool misuse
An agent using a legitimate tool in a harmful way: deleting instead of reading, sending data out, or chaining calls nobody intended. It is ASI02 in the OWASP Top 10 for Agentic Applications (2026).
See alsoExcessive agency, Model Context Protocol (MCP)SourceOWASP Top 10 for Agentic Applications 2026
- Tool poisoning
Hiding instructions or misleading behaviour in a tool's description, metadata or results, so an agent is steered by the tool before or while it uses it. MITRE ATLAS lists AI agent tool poisoning as a technique.
See alsoModel Context Protocol (MCP), Indirect prompt injectionSourceMITRE ATLAS
U
- Unbounded consumption
Letting users or attackers drive an AI application's resource use without limits: long outputs, recursive agent loops, expensive tool calls. It ends in outages or bills. It is LLM06 in the OWASP Top 10 for LLM Applications 2026.
See alsoDenial of walletSourceOWASP Top 10 for LLM Applications 2026
V
- Vector and embedding weaknesses
Weaknesses in how embeddings are created, stored and retrieved: retrieval that crosses tenant boundaries, embeddings that give away the text they were made from, or a vector store more people can write to than should. It is LLM09 in the OWASP 2026 list.
See alsoRetrieval-augmented generation (RAG), Tenant isolationSourceOWASP Top 10 for LLM Applications 2026
- Vulnerability scan
An automated check for known weaknesses, such as outdated software or misconfigurations. It lists what may be wrong; a penetration test shows what an attacker can actually do with it, and what they can chain together.
See alsoPenetration test (pentest)
W
- White box testing
Testing with full access to source code, configuration and architecture. It reaches issues a black box test would need luck to find, at the cost of more reading per day.
See alsoGrey box testing