#160 · LLM Security Testing in DAST: Find AI Vulnerabilities in the Scan You Already Run
Availability: Beta General Availability planned for end of April 2026.
Modern apps ship chatbots, AI agents, RAG endpoints, and copilot features faster than security teams can audit them. Each one is a new attack surface: prompt injection, system prompt leakage, tool exposure, SSRF through model-driven HTTP calls. A traditional DAST scan can't see any of it. LLM Security Testing closes that gap, with automatic discovery and deterministic OWASP LLM Top 10 checks that run inside your existing WebApp, REST API, and GraphQL DAST scans.
What's New¶
- Automatic LLM endpoint discovery: Escape fingerprints LLM traffic from network signals (SSE streaming, OpenAI / Anthropic / Gemini response shapes, token-usage fields), JavaScript source (
openai,@anthropic-ai/sdk,langchain, Vercel AI SDK), and GraphQL operation patterns. No allow-listing, no manual configuration. - Six active OWASP LLM Top 10 checks: prompt injection (LLM01), insecure output handling (LLM02), system prompt leakage (LLM01 + LLM06), LLM command injection (LLM07), LLM-enabled SSRF (LLM07), and tool / function-calling exposure (LLM08).
- Always-on AI inventory: an
ISSUE_LLM_DETECTEDfinding maps every AI endpoint we see, with model, provider, framework, auth posture, and tool exposure. You know where AI lives in your stack before any active probe runs. - Deterministic verification, not an LLM judge: every finding is confirmed by a canary substring, an out-of-band callback, a cloud-metadata marker, or a JSON-schema match. Reproducible, auditable results with no model-driven false positives.
- Runs in the scan you already have: zero new scan profile, zero new infrastructure. Reuses your authenticated session (cookies, bearer tokens, CSRF nonces, persisted GraphQL queries).
Why It Matters¶
"We've got a lot of AI stuff going on, chatbots, AI agents, will that be tested?" is how AppSec leads have been describing their world on our calls. Until now, the honest answer inside a DAST scan was no: prompt injection, system-prompt leakage, and tool exposure don't fall out of standard test catalogues, and AI-judge verification swaps one triage headache for another (non-deterministic AI-vs-AI verdicts). LLM Security Testing gives you a deterministic floor: high-confidence OWASP LLM Top 10 detections, one finding per confirmed issue, with the raw HTTP request and response shipped as audit evidence.
How to Get Started¶
LLM Security Testing is opt-in during the Beta. Reach out through your support channel, the contact form, or support@escape.tech and we'll help you enable it on your scan profile. The knob lives under experimental.llm_security_testing:
On your next scan, every confirmed OWASP LLM Top 10 issue lands in your results with full evidence: prompt sent, response excerpt, matched canary or out-of-band callback, remediation guidance. LLM-enabled SSRF and command injection are confirmed through ssrf.tools.escape.tech, the same out-of-band collector that powers Escape's existing SSRF checks, with per-scan and per-probe identifiers so callbacks are never ambiguous.
By design, no synthetic traffic. Endpoints discovered only via static JavaScript analysis (never exercised by the crawler or recorded in a BLST exchange) get the inventory finding, but the six active checks don't run against them. You only ever see probes against endpoints your application actually serves.
With the knob off, the module adds zero overhead to your normal scan time. Existing DAST scans are unaffected until you opt in.
Compatibility¶
Non-breaking changes¶
- New issue types in scan results:
ISSUE_LLM_DETECTED, prompt injection (LLM01), insecure output handling (LLM02), system prompt leakage (LLM01 + LLM06), LLM command injection (LLM07), LLM-enabled SSRF (LLM07), and tool / function-calling exposure (LLM08). Existing schemas and fields are unchanged; integrations with open-enum issue-type matching pick them up automatically.
What's Next¶
The deterministic module catches what's broken. The other half of AI security is adversarial depth: multi-turn jailbreaks, escalating from a leaked tool schema into a real RCE, pivoting through agent memory, and proving full business-impact exploitation on the most stubborn targets. That's coming to AI Pentesting as the LLM Security Testing Agent, an autonomous, goal-driven adversary that picks up where the deterministic checks leave off, generates new payloads on the fly, and targets RAG pipelines, function-calling chains, MCP servers, and multi-agent orchestrations end-to-end. Want early access? Talk to our team.
Learn More¶
Questions?¶
Have a question? Reach out on your dedicated support channel (Slack, Microsoft Teams, or whichever channel we've set up with your team), or email us at support@escape.tech.