JAVA.SV.LLM.SAFETY.DISABLED

LLM safety filter disabled

The JAVA.SV.LLM.SAFETY.DISABLED checker flags code that disables an LLM provider's safety filtering instead of leaving a blocking threshold in place.

Vulnerability and risk

Disabling safety filters can allow prompts or generated responses to bypass provider-side protections for dangerous or harmful content. This increases the risk that the application will process or return unsafe content.

Mitigation and prevention

Keep the provider's safety checks enabled and configure an explicit blocking threshold that matches your application's safety requirements. Review any override of safety settings before deployment.

Vulnerable code example 1

Copy
import com.google.genai.types.GenerateContentConfig;
import com.google.genai.types.HarmBlockThreshold;
import com.google.genai.types.SafetySetting;

public class Example {
    public GenerateContentConfig configure() {
        return GenerateContentConfig.builder()
                .safetySettings(SafetySetting.builder()
                        .category("HARM_CATEGORY_DANGEROUS_CONTENT")
                        .threshold(HarmBlockThreshold.Known.OFF) // OFF disables the content filter
                        .build())
                .build();
    }
}

Klocwork reports a JAVA.SV.LLM.SAFETY.DISABLED defect on line 10 because the safety threshold is set to OFF.

Fixed code example 1

Copy
import com.google.genai.types.GenerateContentConfig;
import com.google.genai.types.HarmBlockThreshold;
import com.google.genai.types.SafetySetting;

public class Example {
    public GenerateContentConfig configure() {
        return GenerateContentConfig.builder()
                .safetySettings(SafetySetting.builder()
                        .category("HARM_CATEGORY_DANGEROUS_CONTENT")
                        .threshold(HarmBlockThreshold.Known.BLOCK_MEDIUM_AND_ABOVE) // real threshold keeps the filter on
                        .build())
                .build();
    }
}

In this fixed example, Klocwork no longer reports a JAVA.SV.LLM.SAFETY.DISABLED defect because the safety threshold remains enabled.

Security training

Application security training materials provided by Secure Code Warrior.

Extension

This checker cannot be extended through the Klocwork knowledge base.