Prompt pack · audit, attack, prove
Verify. Attack. Prove. Not write.

AISVS Verification & AI-DAST Prompt Pack

Prompts that audit an AI system against the OWASP AISVS standard, attack it to surface the failures, and produce the evidence. Not prompts that write code. Prompts that verify it.

Not generation. Verification.

AI is writing your stack. Can you prove it is secure?

Generation prompts help AI write code. These do the opposite job. They audit, attack and verify an AI system against AISVS, and produce a defensible finding for every requirement. The question is no longer whether AI can write it. It is whether you can prove it meets the standard.

TOOL-101. In the pack

176 prompts across all 12 AISVS categories

Each prompt maps to a specific AISVS requirement ID. Output feeds directly into gap assessments, audit reports and signed evidence packs.

Audit Prompts by AISVS Category

One Set per Control Family

P-00 Governance and Risk (C01) 12 prompts

Prompts that assess whether governance documentation exists, whether risk assessments cover AI-specific threats, and whether ownership is assigned. These produce structured findings suitable for a gap report.

P-01 Input Validation (C02) 18 prompts

Prompts that test input sanitization, prompt injection resistance, PII detection and boundary enforcement. Includes both "does the control exist" assessment prompts and adversarial test prompts that probe whether the control actually holds.

P-02 Model Lifecycle (C03) 10 prompts

Prompts that verify model provenance documentation, check whether versioning and approval processes are in place, and test whether the deployed model matches the approved model.

P-03 Model Serving (C04) 14 prompts

Prompts that assess inference endpoint configuration, test authentication and rate limiting, and verify response header hygiene. Includes prompts that generate the curl commands to test each control.

P-04 Access Control and Identity (C05) 16 prompts

Prompts that assess authorization policies, test for privilege escalation paths, verify fail-closed behaviour and check agent identity credential validity.

P-05 Supply Chain (C06) 12 prompts

Prompts that assess dependency management practices, verify SBOM completeness, and test whether vulnerability scanning is configured and actually blocking.

Audit Prompts (continued)

C07 through C12

P-06 Output Validation (C07) 14 prompts

Prompts that test output redaction controls, verify encoding prevents downstream injection, and probe for sensitive data leakage through model responses.

P-07 Data Protection (C08) 12 prompts

Prompts that assess vector store access controls, test cross-tenant retrieval isolation, and verify encryption at rest for the knowledge store.

P-08 Orchestration and Agents (C09) 18 prompts

Prompts that assess agent trust boundaries, test delegation chain controls, verify human-in-the-loop gates on critical actions, and check signed execution receipts.

P-09 MCP and Plugins (C10) 16 prompts

Prompts that assess MCP server configuration, test tool integrity controls, probe for replay vulnerabilities, and verify per-message signing. Maps to the OWASP MCP Top 10.

P-10 Adversarial Robustness (C11) 20 prompts

Prompts that run adversarial tests against guardrails, test jailbreak resistance, probe for data extraction, and verify that robustness controls produce measurable results.

P-11 Monitoring and Audit (C12) 14 prompts

Prompts that assess logging completeness, verify tamper-evidence on audit trails, test anomaly detection coverage, and check that monitoring is reviewed, not just configured.

How to Use

Run, Map, Customize

U-00 Running the Prompts

How to run each prompt category, what input it needs (system description, configuration exports, access to endpoints), and how to interpret the output.

U-01 Mapping Output to AISVS

Every prompt output includes the AISVS requirement ID it maps to. How to take the output and drop it into a gap assessment spreadsheet or audit report as evidence.

U-02 Customizing for Your Stack

How to adapt the prompts for your specific technology stack, cloud provider and organizational context without breaking the AISVS mapping.

176
Total prompts
12
AISVS categories covered
AISVS 1.0
Aligned to current release
Self-paced
No instructor required
Why these are different

These prompts have teeth.

They do not just emit text. They drive CLAW for technical enumeration and return findings mapped to AISVS requirement IDs, with evidence you can sign. Not suggestions. Proof.

Provable AI

From "we think it is secure" to "here is the proof"

Every finding is evidence-backed, mapped to a requirement, and can be cryptographically signed into a tamper-evident record. Verification you can hand to an auditor, a board, or a regulator.

Who it is for

Built for the people who verify, not just build

Security auditors

Run AISVS assessments with a method, not guesswork.

Penetration testers

Attack AI systems and map every finding to the standard.

AppSec & security teams

Verify the AI your developers and their assistants ship.

GRC & compliance

Turn AISVS into evidence and findings that hold up.

Consultants

Deliver paid AISVS assessments at speed.

Certified AISVS auditors

The toolkit behind the auditor credential.

Licensing

Verify what your AI writes.

Licensed to security teams and certified AISVS auditors. Private and proprietary. Drives CLAW and ships with the agent-skills and AI-DAST engine.

Per team or per auditor Private and proprietary Drives CLAW + signed evidence
Request a Licence

Enterprise and sovereign licences, on request.