Skip to content

Securing LLM Application Outputs

Why model output must be treated as untrusted input to other systems, and how to avoid injection and unsafe actions.

Editorial team 1 min read

Model output often flows into other systems: web pages, databases, shells, emails. Treating it as trusted is a common and serious mistake.

Risks

  • Cross-site scripting: model output rendered as HTML can include malicious scripts.
  • SQL injection: generated queries executed without safeguards.
  • Command injection: output passed to shells.
  • Server-side request forgery: model-chosen URLs fetched by servers.
  • Data exfiltration: output containing links or images that send data to attackers when rendered.

Defences

  • Encode output appropriately for its context — HTML-escape text displayed in web pages.
  • Sanitise Markdown and HTML before rendering; restrict links and images to trusted domains.
  • Parameterised queries and read-only database accounts for generated SQL.
  • Allow-lists for commands, URLs and file paths.
  • Schema validation for structured output.
  • Sandbox execution of generated code.

Principle

Apply the same controls you would to user input. The model may have been influenced by an attacker, directly or through content it read.

More in AI security

All AI security guides →
AI security Guide · 1 min

Introduction to AI Security

What AI security covers — attacks on models, data and AI applications — and how it differs from traditional security.

AI security 1 min read 29 Jun 2025

AI security Guide · 1 min

The OWASP Top 10 for LLM Applications

An overview of the widely used list of the most critical security risks for applications built on language models.

AI security 1 min read 28 Jun 2025

AI security Guide · 1 min

Jailbreaks: How They Work and How to Defend

How people try to get models to bypass their safety training, common techniques, and layered defences.

AI security 1 min read 27 Jun 2025

AI security Guide · 1 min

Indirect Prompt Injection

How attackers hide instructions in web pages, emails and documents that AI systems read, and why it's so dangerous for agents.

AI security 1 min read 26 Jun 2025