Hidden Context Exposure

LLM08:2026 in the OWASP LLM Top 10, which replaced System Prompt Leakage: extracting, inferring or reconstructing the hidden context a model sees, such as system prompts, developer instructions, retrieved policy text and tool schemas 1. The advice is to assume hidden context is discoverable, keep credentials out of it and never rely on it as a security boundary.

Developed in
ch. 23, Prompts as configuration under change control
Chapters
ch. 23, AI Agents
Contrast with
Prompt injection
Source
1 numbered reference, listed below

Where it is used

One chapter of the Body of Knowledge uses the term. Each link opens the first section that does.

Sources

  1. [1] OWASP GenAI LLM Top 10 2026 (published 3 Aug 2026; LLM01:2026 Prompt Injection, incl. memory persistence; LLM08:2026 Hidden Context Exposure, which replaced System Prompt Leakage: assume hidden context is discoverable, no credentials in it, not a security boundary; final text in github.com/GenAI-Security-Project/GenAI-LLM-Top10, 2026/final). OWASP GenAI Security Project. 2026-08-03. https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/ (verified: primary)

Definitions of legal terms paraphrase the cited text, which governs. Dated statements are as of .

Cite this term

García Aibar, J. (2026). Hidden Context Exposure. In AI Governance Engineering: The Thesis & Body of Knowledge (v0.5.0), Glossary. https://doi.org/10.5281/zenodo.22956197. https://aigovernanceengineer.com/glossary/hidden-context-exposure. CC BY 4.0

BibTeX

@misc{aige2026hiddencontextexposure,
  author  = {Jorge García Aibar},
  title   = {{Hidden Context Exposure}},
  note    = {Glossary, AI Governance Engineering: The Thesis \& Body of Knowledge, version 0.5.0},
  year    = {2026},
  doi     = {10.5281/zenodo.22956197},
  url     = {https://aigovernanceengineer.com/glossary/hidden-context-exposure}
}