Reference / Glossary

AI and offensive security glossary.

The words we use in scopes, reports and research, defined the way we use them. Each entry answers first, names the framework id where one exists, and links its source. Two layers, model and stack, plus the process and standards that hold a test together.

Updated
Sources
14
FIG. 1 / THE GLOSSARY BY LAYER

53Terms defined

Model layer
24
Stack layer
12
Process and standards
17

All terms

A

Agent goal hijackASI01Model layer

Redirecting an agent away from the goal its user or developer gave it, usually through content it reads, so it pursues another goal with the user's permissions. It is ASI01 in the OWASP Top 10 for Agentic Applications (2026).

See alsoAI agent, Indirect prompt injectionSourceOWASP Top 10 for Agentic Applications 2026

AI agentModel layer

An AI system that pursues a goal over several steps by choosing and calling tools, such as reading mail, querying an API or writing a file. Acting on someone's behalf is what makes it useful, and what makes everything it reads a security boundary.

See alsoExcessive agency, Agent goal hijack, Model Context Protocol (MCP)

AI red teamingModel layer

Authorized adversarial testing of an AI system. Testers attack the model, its prompts, its data sources and its tools the way a real attacker would, to find exploitable failures before customers or attackers do.

See alsoLLM penetration test, Prompt injection

Attack surfaceStack layer

Everything an attacker can reach and influence: endpoints, accounts, integrations and, for AI features, every source of text the model reads.

See alsoScope

Attestation letterProcess and standards

A one-page letter stating the scope, dates and outcome of a test, so you can show a customer or an auditor that it happened without sharing the findings.

See alsoScope, Finding

Authorization letter (vrijwaringsverklaring)Process and standards

The written permission from a system's owner that makes a test lawful. Without it, a penetration test is an attack. For anything a vendor hosts, the vendor's permission is needed as well.

See alsoRules of engagement

B

Black box testingStack layer

Testing with no inside knowledge, the way an outside attacker starts: no source code, no architecture notes, often no account.

See alsoGrey box testing, White box testing

Broken function level authorizationAPI5:2023Stack layer

An API letting a caller use a function their role should not reach, such as an administrative action called with a normal user's account. It is API5 in the OWASP API Security Top 10 (2023).

See alsoBroken object level authorization (BOLA)SourceOWASP API Security Top 10 2023

Broken object level authorization (BOLA)API1:2023Stack layer

An API returning or changing an object, such as an invoice or a claim, without checking that the caller may access that specific object. It is API1 in the OWASP API Security Top 10 (2023).

See alsoTenant isolation, Broken function level authorizationSourceOWASP API Security Top 10 2023

Business logic flawWSTG-BUSLStack layer

A flaw in how an application's rules work rather than in its code's syntax: skipping a payment step, applying a discount twice, approving your own request. Scanners do not know your rules, so these need a person. The OWASP Web Security Testing Guide tests them as a category of its own.

See alsoPenetration test (pentest)SourceOWASP Web Security Testing Guide 4.2

C

Coordinated vulnerability disclosure (CVD)Process and standards

Reporting a vulnerability privately to whoever can fix it, and publishing only after a fix or an agreed deadline. Ours is on the disclosure policy page.

See alsosecurity.txt

Cross-layer findingStack layer

A finding that starts in one layer and ends in the other: a prompt injection that reaches an API without authorization checks, or a tool call that reads another tenant's data. Our reports list these paths separately, because neither a model test nor a stack test alone would find them.

See alsoImproper output handling, Tenant isolation

CVSS v4.0Process and standards

Version 4.0 of the Common Vulnerability Scoring System, maintained by FIRST: a standard way to rate a vulnerability's severity from its exploitability and impact, as a score from 0.0 to 10.0.

See alsoFindingSourceFIRST, CVSS v4.0 specification

D

Data and model poisoningLLM05:2026Model layer

Manipulating the data a model is trained, fine-tuned or grounded on, or a pre-trained component it is built from, to plant weaknesses, bias or hidden behaviour. It is LLM05 in the OWASP 2026 list, and the EU AI Act names data poisoning and model poisoning among the attacks high-risk systems must resist.

See alsoRAG poisoning, EU AI ActSourceOWASP Top 10 for LLM Applications 2026, AI Act Art. 15(5)

Denial of walletModel layer

An attack that inflates an AI application's usage costs until the invoice, rather than the server, becomes the outage. OWASP covers it under LLM06:2026 Unbounded Consumption; MITRE ATLAS calls the technique cost harvesting.

See alsoUnbounded consumptionSourceOWASP Top 10 for LLM Applications 2026, MITRE ATLAS

E

EU AI ActProcess and standards

Regulation (EU) 2024/1689, the EU law on artificial intelligence. Its Article 15 asks high-risk AI systems for accuracy, robustness and cybersecurity, from 2 December 2027 for Annex III systems. More on our Article 15 page.

See alsoNIS2, Data and model poisoningSourceAI Act Art. 15, AI Omnibus, Art. 113(c)

Excessive agencyLLM03:2026Model layer

The risk that an LLM-based system takes damaging actions because it has more tools, permissions or autonomy than its task needs. It is LLM03 in the OWASP Top 10 for LLM Applications 2026.

See alsoAI agent, Tool misuseSourceOWASP Top 10 for LLM Applications 2026

F

FindingProcess and standards

One confirmed security issue in a report: what it is, where it is, what an attacker could do with it, how severe it is, and how to fix it.

See alsoCVSS v4.0, Retest, Reproduction rate

G

Grey box testingStack layer

Testing with partial knowledge: typically an account for each role, API documentation and, for AI features, the system prompt and tool definitions. It gives the most coverage per testing day.

See alsoBlack box testing, White box testing

GuardrailModel layer

A control that filters or constrains what goes into or comes out of a model: input classifiers, output filters, policy prompts. Useful, and never a substitute for testing, because a guardrail is itself something an attacker probes.

See alsoJailbreak, AI red teaming

H

Hidden context exposureLLM08:2026Model layer

An AI application revealing context its users were never meant to see, such as its system prompt, hidden instructions or the configuration they describe. It is LLM08 in the OWASP Top 10 for LLM Applications 2026; MITRE ATLAS lists extracting a system prompt as a technique.

See alsoSensitive information disclosureSourceOWASP Top 10 for LLM Applications 2026, MITRE ATLAS

I

Identity and privilege abuseASI03Model layer

An agent acting with credentials or permissions broader than its task, or borrowing a user's identity in a way someone else can exploit. It is ASI03 in the OWASP Top 10 for Agentic Applications (2026).

See alsoExcessive agency, Tenant isolationSourceOWASP Top 10 for Agentic Applications 2026

Improper output handlingLLM10:2026Model layer

Passing model output to other systems without validating it, so text from the model can become script in a browser, a query in a database or a command on a server. It is LLM10 in the OWASP 2026 list.

See alsoCross-layer findingSourceOWASP Top 10 for LLM Applications 2026

Indirect prompt injectionAML.T0051.001Model layer

Prompt injection delivered through content the model retrieves or processes, such as a web page, a RAG passage, an email or a tool result, instead of through the chat box. The attacker never has to talk to the system, which is why it matters most for agents.

See alsoPrompt injection, RAG poisoningSourceMITRE ATLAS

J

JailbreakAML.T0054Model layer

An attempt to make a model ignore its safety training. Prompt injection targets the application's instructions instead. MITRE ATLAS lists LLM jailbreak as its own technique.

See alsoPrompt injection, GuardrailSourceMITRE ATLAS

L

LLM penetration testModel layer

A scoped, time-boxed security assessment of an application built on a large language model. It covers the model's inputs and outputs and everything the model can reach: retrieval sources, tools, APIs, user data and other tenants.

See alsoAI red teaming, Penetration test (pentest)

M

Memory and context poisoningASI06Model layer

Planting content in an agent's memory or conversation context so that it shapes later decisions, for the same user or for others. It is ASI06 in the OWASP Top 10 for Agentic Applications (2026).

See alsoRAG poisoning, AI agentSourceOWASP Top 10 for Agentic Applications 2026

MITRE ATLASProcess and standards

MITRE's knowledge base of adversary tactics and techniques against AI systems, with ids such as AML.T0051 for LLM prompt injection. We map AI findings to it alongside the OWASP lists.

See alsoOWASP Top 10 for LLM ApplicationsSourceMITRE ATLAS

Model Context Protocol (MCP)Model layer

An open-source standard for connecting AI applications to external systems: data sources, tools and workflows. An MCP server exposes tools; an agent that connects to it trusts their descriptions and their results.

See alsoTool poisoning, AI agentSourcemodelcontextprotocol.io

N

NIS2Process and standards

The EU directive on a high common level of cybersecurity, Directive (EU) 2022/2555. Its Dutch implementation, the Cyberbeveiligingswet, has applied since 15 August 2026. More on our NIS2 page.

See alsoEU AI ActSourceNIS2 Directive, OJ L 333, Staatsblad 2026, 189

O

OWASP API Security Top 10Process and standards

OWASP's list of the ten most critical API security risks. The current edition is from 2023 and starts with broken object level authorization, API1:2023.

See alsoBroken object level authorization (BOLA), OWASP Web Security Testing Guide (WSTG)SourceOWASP API Security Top 10 2023

OWASP Top 10 for Agentic ApplicationsProcess and standards

OWASP's list of the ten most critical risks for AI agents, with ids ASI01 to ASI10, published in December 2025 as the 2026 edition.

See alsoAgent goal hijack, Tool misuseSourceOWASP GenAI

OWASP Top 10 for LLM ApplicationsProcess and standards

OWASP's list of the ten most critical risks for applications built on large language models, with ids LLM01 to LLM10. The 2026 edition was published in August 2026, with prompt injection first.

See alsoPrompt injection, OWASP Top 10 for Agentic ApplicationsSourceOWASP GenAI

OWASP Web Security Testing Guide (WSTG)Process and standards

OWASP's guide to testing the security of web applications, organised in 12 categories such as authorization (WSTG-ATHZ) and business logic (WSTG-BUSL). We map stack findings to it.

See alsoOWASP API Security Top 10, Business logic flawSourceOWASP Web Security Testing Guide 4.2, OWASP WSTG

P

Penetration test (pentest)Stack layer

An authorized, simulated attack by security specialists that proves which vulnerabilities are actually exploitable, followed by a report with evidence, risk ratings and concrete fixes.

See alsoVulnerability scan, Scope

Prompt injectionLLM01:2026Model layer

An attack in which text processed by a large language model, typed by a user or hidden in a document, email or web page, overrides the developer's instructions. OWASP ranks it first in its Top 10 for LLM Applications 2026.

See alsoIndirect prompt injection, JailbreakSourceOWASP Top 10 for LLM Applications 2026

R

RAG poisoningAML.T0070Model layer

Planting malicious or misleading content in the documents a RAG system searches, so the model repeats it as fact or follows instructions hidden inside it. MITRE ATLAS lists it as a technique.

See alsoRetrieval-augmented generation (RAG), Indirect prompt injection, Data and model poisoningSourceMITRE ATLAS

Regression packProcess and standards

Each confirmed finding turned into a test you can rerun: an HTTP request collection for stack findings; prompt sets, injected documents and tool-call traces for AI findings. It turns a one-off test into a check for the next release.

See alsoRetest

Reproduction rateModel layer

How often a finding reproduces across repeated attempts, reported as n of 10 with the model and its settings recorded. Models are probabilistic, so one successful attempt is an anecdote and 7 of 10 is a measurement.

See alsoFinding

RetestProcess and standards

Testing a finding again after it was fixed, to confirm that the fix works and did not open something else. The result goes into the report as the finding's status.

See alsoRegression pack, Finding

Retrieval-augmented generation (RAG)Model layer

A design in which an AI application searches a document store for passages relevant to a question and hands them to the model as context. Everything in that store can steer the answer, so the store is part of the attack surface.

See alsoRAG poisoning, Vector and embedding weaknesses

Rules of engagementProcess and standards

The written agreement on how a test runs: the window, rate limits, contacts on both sides, what is off limits, and how one message stops all testing. Ours are on the rules of engagement page.

See alsoScope, Authorization letter (vrijwaringsverklaring)

S

ScopeProcess and standards

The systems, accounts, environments and time window a test covers, agreed in writing before it starts. What is out of scope is written down too, so the report's blind spots are on record.

See alsoRules of engagement, Attack surface

security.txtProcess and standards

A text file at /.well-known/security.txt that tells researchers where to report a vulnerability and which policy applies. RFC 9116 defines it, and requires an Expires date so stale contacts age out. Ours is live.

See alsoCoordinated vulnerability disclosure (CVD)SourceRFC 9116

Sensitive information disclosureLLM02:2026Model layer

An AI application revealing data it should not, such as personal data, credentials, another customer's records or confidential business data, through its answers or its actions. It is LLM02 in the OWASP Top 10 for LLM Applications 2026.

See alsoTenant isolation, Vector and embedding weaknessesSourceOWASP Top 10 for LLM Applications 2026

Server-side request forgery (SSRF)API7:2023Stack layer

Making a server send requests to a destination of the attacker's choosing, often internal systems or a cloud metadata service the attacker cannot reach directly. It is API7 in the OWASP API Security Top 10 (2023).

See alsoCross-layer findingSourceOWASP API Security Top 10 2023

T

Tenant isolationStack layer

In a multi-tenant SaaS product, the guarantee that one customer can never read or change another's data. It is enforced in many places at once, from API authorization to storage and AI retrieval, so it is tested end to end.

See alsoBroken object level authorization (BOLA), Vector and embedding weaknesses

Tool misuseASI02Model layer

An agent using a legitimate tool in a harmful way: deleting instead of reading, sending data out, or chaining calls nobody intended. It is ASI02 in the OWASP Top 10 for Agentic Applications (2026).

See alsoExcessive agency, Model Context Protocol (MCP)SourceOWASP Top 10 for Agentic Applications 2026

Tool poisoningAML.T0110Model layer

Hiding instructions or misleading behaviour in a tool's description, metadata or results, so an agent is steered by the tool before or while it uses it. MITRE ATLAS lists AI agent tool poisoning as a technique.

See alsoModel Context Protocol (MCP), Indirect prompt injectionSourceMITRE ATLAS

U

Unbounded consumptionLLM06:2026Model layer

Letting users or attackers drive an AI application's resource use without limits: long outputs, recursive agent loops, expensive tool calls. It ends in outages or bills. It is LLM06 in the OWASP Top 10 for LLM Applications 2026.

See alsoDenial of walletSourceOWASP Top 10 for LLM Applications 2026

V

Vector and embedding weaknessesLLM09:2026Model layer

Weaknesses in how embeddings are created, stored and retrieved: retrieval that crosses tenant boundaries, embeddings that give away the text they were made from, or a vector store more people can write to than should. It is LLM09 in the OWASP 2026 list.

See alsoRetrieval-augmented generation (RAG), Tenant isolationSourceOWASP Top 10 for LLM Applications 2026

Vulnerability scanStack layer

An automated check for known weaknesses, such as outdated software or misconfigurations. It lists what may be wrong; a penetration test shows what an attacker can actually do with it, and what they can chain together.

See alsoPenetration test (pentest)

W

White box testingStack layer

Testing with full access to source code, configuration and architecture. It reaches issues a black box test would need luck to find, at the cost of more reading per day.

See alsoGrey box testing