OWASP’s canonical list of what goes wrong with LLM applications: prompt injection, sensitive information disclosure, supply chain, data/model poisoning, improper output handling, excessive agency, system prompt leakage, embedding weaknesses, misinformation, unbounded consumption.

My favorite explanation of prompt injection: the kid who’s told “don’t say you’re a Madrid fan”, and when the Atlético player asks him which team he supports, answers “no te lo puedo decir”. Practice it in the Gandalf game.