Red-teaming your own LLM stack
Published 14 February 2026 · Editorial update 6 September 2026 · 2 min read · Enternovate

An LLM application combines a model, instructions, retrieved content and tools. A useful security test checks the whole system. The OWASP guidance for LLM applications provides a starting taxonomy, not an automatic certification.
Use a test environment with synthetic records and credentials that cannot reach production. Define authorised scope and prohibited actions before testing. Do not use real client secrets to prove that a model can leak data.
Test instructions embedded in retrieved documents, cross-user data access and attempts to invoke tools beyond their permissions. Check that the application treats retrieved text as data, not as authority to change its operating rules.
Record the input, tool calls, outcome and expected boundary. An LLM judge can help triage results, but a human should review consequential findings. Add reproducible failures to a regression suite and repeat it when models, prompts or tools change.
Mhangani is our web-security audit tool; it should not be described as proof that every Xavani release passed an LLM attack suite. A scoped AI-security engagement needs its own test plan, evidence and remediation review. Ask us to agree that scope before testing.