13 min read
OWASP LLM Top 10 in practice: what to test, how to defend, where MCP changes the threat model
A working engineer's read of OWASP LLM Top 10 — prompt injection through RAG, tool calling risks, MCP-specific exposures, and the four-layer defense pattern that actually holds up in production.