Repeated findings are useful only when they stay accurate. The OWASP AISVS Default Findings Engine lets an authorized team leader or admin save a reusable starting point against a canonical AI security requirement. It reduces repeated typing while leaving the actual observation, evidence, scope, and validation inside each project finding.
What this solves
AI red teams repeatedly observe prompt injection, unsafe tool calls, data leakage, retrieval poisoning, weak output handling, model supply-chain issues, and missing monitoring. Test transcripts can contain sensitive prompts or user data, and one successful probe can be overgeneralized without repeatability or application context.
Before you begin
- Sign in as a team leader or team admin with access to the local engine.
- Confirm that OWASP AISVS is the correct Library for the work.
- Choose a recurring issue pattern, not one client-specific finding.
- Remove names, URLs, selectors, credentials, personal data, dates, and evidence from the reusable wording.
- Keep the official OWASP Artificial Intelligence Security Verification Standard (AISVS) scope and terminology available for reference.
Step-by-step
- Define the AI system type, model boundary, tools, data flows, and authorized test scope.
- Open the AISVS local engine and choose the most precise requirement.
- Describe the reusable application-control failure rather than one surprising response.
- State the security consequence, preconditions, and expected protective behavior.
- Add remediation across application, tool, data, policy, or monitoring controls as appropriate.
- Keep real prompts, outputs, accounts, models, repetitions, and evidence in the project finding.
What the default saves
A local default can save the summary, description, remediation guidance, severity behavior, and canonical AI security requirement mapping. When a reviewer selects it from New Finding, voiqq prefills those values. The new finding still starts Open with Pending validation and must be changed to match the real observation.
Good patterns to predefine
- Untrusted instructions override higher-priority application controls through direct or indirect prompt injection.
- An agent invokes a privileged tool without checking the authenticated caller and requested resource.
- Sensitive information enters prompts, retrieval context, model output, or retained provider data unnecessarily.
- Model output reaches an interpreter, browser, workflow, or downstream system without safe handling.
- AI security events lack the prompt, policy, tool, model, and response context needed for investigation.
Check your result
- Do not place sensitive prompts, outputs, API keys, or personal data in a default.
- Distinguish model behavior from application authorization and integration failures.
- Require repeatability and context before setting final severity.
- Map to the most specific supported AISVS requirement.
- Retest the complete application path, not only the model.
voiqq uses the stable OWASP AISVS 1.0 catalogue: 191 requirements in 12 chapters with verification levels 1, 2, and 3. AISVS requirements are assessment requirements, not prewritten findings; several findings can be connected to one requirement when the evidence warrants it.
