LLM08:2026 in the OWASP LLM Top 10, which replaced System Prompt Leakage: extracting, inferring or reconstructing the hidden context a model sees, such as system prompts, developer instructions, retrieved policy text and tool schemas 1. The advice is to assume hidden context is discoverable, keep credentials out of it and never rely on it as a security boundary.
- Developed in
- ch. 23, Prompts as configuration under change control
- Chapters
- ch. 23, AI Agents
- Contrast with
- Prompt injection
- Source
- 1 numbered reference, listed below
Where it is used
One chapter of the Body of Knowledge uses the term. Each link opens the first section that does.
- 23 · AI Agents Prompts as configuration under change control 2 mentions
Related terms
Sources
- [1] OWASP GenAI LLM Top 10 2026 (published 3 Aug 2026; LLM01:2026 Prompt Injection, incl. memory persistence; LLM08:2026 Hidden Context Exposure, which replaced System Prompt Leakage: assume hidden context is discoverable, no credentials in it, not a security boundary; final text in github.com/GenAI-Security-Project/GenAI-LLM-Top10, 2026/final). OWASP GenAI Security Project. 2026-08-03. https://genai.owasp.org/resource/owasp-genai-llm-top-10-2026/ (verified: primary)
Definitions of legal terms paraphrase the cited text, which governs. Dated statements are as of .