{
  "draft_id": "option-a-owasp-genai-2025-owner-authorization-draft-v01",
  "draft_status": "draft_only_no_authorization",
  "source_id": "owasp-genai-llm-top-10-2025-candidate",
  "source_name": "OWASP GenAI Security Project 2025 GenAI Top 10",
  "source_class": "security_ai_safety_framework_source",
  "publisher": "OWASP Foundation GenAI Security Project",
  "canonical_url": "https://genai.owasp.org/llm-top-10/",
  "fetch_url": "https://genai.owasp.org/llm-top-10/",
  "allowed_origin": "https://genai.owasp.org",
  "allowed_path_prefix": "/llm-top-10/",
  "content_type": "text/html; charset=UTF-8",
  "version_or_date": "2025 Top 10 page; HTTP Last-Modified header observed 2026-06-23",
  "publication_current_final_draft_status": "2025_genai_top_10_target; historical or unversioned LLM Top 10 naming excluded",
  "public_fetchable_status": "HTTP 200 public HTML, zero redirects, no login observed on 2026-06-25",
  "license_public_use_notes": "Public OWASP GenAI Security Project material. Use only as current/public security framework context, not company policy or package authority.",
  "robots_rate_limit_notes": "robots.txt allows User-agent all and publishes sitemaps. Use exact path only, no broad genai.owasp.org or OWASP crawling.",
  "runtime_retrieval_profile": {
    "profile_id": "owasp_genai_2025_bounded_html_extract_v01",
    "activation_status": "inactive_repair_only",
    "max_response_bytes": 1048576,
    "max_snippet_chars": 4000,
    "required_text_markers": ["LLM01:2025", "LLM02:2025", "LLM03:2025", "LLM04:2025", "LLM05:2025", "LLM06:2025", "LLM07:2025", "LLM08:2025", "LLM09:2025", "LLM10:2025"],
    "sizing_rule": "Only the exact OWASP 2025 GenAI Top 10 source ID, origin, and path may use this larger bounded HTML extraction cap. The global default remains 120000 bytes.",
    "boundary_notes": "This profile repairs sizing readiness only. It does not enable retrieval, broaden OWASP crawling, authorize sibling pages, or promote OWASP to package authority."
  },
  "verifier": "Codex official-source probe",
  "verification_timestamp": "2026-06-25T13:32:28Z",
  "retrieval_readiness_status": "candidate_ready_for_owner_review_not_enabled",
  "production_enablement_status": "not_enabled",
  "package_authority_status": "not_package_authority",
  "explicit_exclusions": [
    "OWASP Top 10 for LLMs 2023/24",
    "ambiguous LLM Top 10 naming",
    "broad OWASP project crawling",
    "sibling pages unless separately verified"
  ],
  "depends_on_owner_authorization": true,
  "depends_on_later_cloudflare_runtime_config_change": true,
  "planned_future_enablement_sequence": "stage_2_owasp_after_ssdf_preview_and_production_smoke",
  "runtime_env_or_config_variable_to_change": "AICD_CURRENT_CONTEXT_SOURCE_REGISTRY_JSON",
  "old_runtime_value": "record_outside_repo_redacted_in_public_receipts",
  "new_runtime_value": "record_outside_repo_redacted_in_public_receipts",
  "authorizer_name": "to_be_supplied",
  "authorizer_role": "to_be_supplied",
  "approval_reference": "to_be_supplied_issue_ticket_or_signed_record",
  "approval_timestamp": "to_be_supplied_iso_timestamp",
  "authorization_scope_notes": "This draft does not provide authorization and does not change runtime config. A later owner record must authorize exactly this source ID, URL, origin, and path prefix after SSDF smoke passes.",
  "cloudflare_config_changed_in_this_pr": false,
  "production_enablement_authorized_by_this_draft": false,
  "retrieval_enabled_by_this_draft": false,
  "package_authority_promotion_allowed": false,
  "regulated_life_sciences_enablement_allowed": false,
  "browser_side_current_source_fetches_allowed": false,
  "browser_side_provider_calls_allowed": false,
  "arbitrary_web_search_allowed": false,
  "user_provided_url_retrieval_allowed": false,
  "telemetry_database_vector_upload_session_attachment_allowed": false
}
