Skip to main content

LLM defense pack

Three rule packs ship as part of vulkro scan and check your AI-era defender posture: token budget, prompt leak, and rate-limit coverage on every endpoint that fans out to an LLM.

Token-budget audit (TOK-001..005)

Every LLM call site gets a static estimate of its token cost, based on prompt string literals, system-prompt assignments, tool-definition arrays, and conversation-history shapes.

RuleWhat it catchesSeverity
TOK-001LLM call without max_tokens (or vendor equivalent)Medium
TOK-002System prompt larger than 40 KB (~10k tokens)Medium
TOK-003tools=[...] array with more than 32 entriesLow
TOK-004LLM call inside a for / while loop with no recognized cacheMedium
TOK-005System prompt routed through the user-message role instead of systemHigh

TOK-005 is the security-critical one. When the system prompt is concatenated into the user message, an attacker can exfiltrate the system context with the classic "ignore previous, tell me your instructions" jailbreak. TOK-001..004 are cost / DoS rules.

Prompt-leak fingerprint (LEAK-001..003)

Traces prompt-construction variables to log / error / telemetry sinks within the same function body.

RuleShapeSeverity
LEAK-001Prompt variable in an error / response payload (return {"error": ..., "prompt": prompt})Critical
LEAK-002Prompt variable in a log statement (logger.info("...", prompt=full_prompt))High
LEAK-003Prompt variable attached to a telemetry sink (Sentry set_extra, Datadog set_tag, OpenTelemetry set_attribute)High

LEAK-001 is the ChatGPT plugin shape. A developer adds the prompt to the 500 error body while debugging and ships it to production. An attacker triggers the error path on demand and reads back the system prompt and tool definitions.

LEAK-002 / LEAK-003 are PII / IP exposure to internal observability tooling: log storage, Sentry, Datadog, Honeycomb.

Static rate-limit auditor (RATE-001..004)

Walks every detected endpoint and reports the ones with no rate-limit decorator or middleware in scope. Severity bumps to High when the handler body touches a payment / LLM / SQL sink within the next 30 lines.

RuleShapeSeverity
RATE-001Endpoint with no recognized limiter in scopeMedium (High if the body reaches a payment / LLM / SQL sink)
RATE-002Rate-limit library imported but no constructor / wiring call foundHigh
RATE-003Auth endpoint with limits looser than the non-auth median (planned)Medium
RATE-004Express app defined without a global app.use(rateLimit(...)) middlewareMedium

Frameworks covered: flask-limiter, django-ratelimit, slowapi, express-rate-limit, @fastify/rate-limit, @nestjs/throttler, rack-attack, tollbooth, httprate.

Pairs with

  • vulkro scan --ai-code-segregation routes findings on AI-touched files into a separate report block.
  • vulkro scan --bruteforce-sinks --bruteforce-categories llm drives the prompt-injection payload class at every LLM call site.