JAVA.SV.LLM.SAFETY.DISABLED
LLM safety filter disabled
The JAVA.SV.LLM.SAFETY.DISABLED checker flags code that disables an LLM provider's safety filtering instead of leaving a blocking threshold in place.
Vulnerability and risk
Disabling safety filters can allow prompts or generated responses to bypass provider-side protections for dangerous or harmful content. This increases the risk that the application will process or return unsafe content.
Mitigation and prevention
Keep the provider's safety checks enabled and configure an explicit blocking threshold that matches your application's safety requirements. Review any override of safety settings before deployment.
Vulnerable code example 1
import com.google.genai.types.GenerateContentConfig;
import com.google.genai.types.HarmBlockThreshold;
import com.google.genai.types.SafetySetting;
public class Example {
public GenerateContentConfig configure() {
return GenerateContentConfig.builder()
.safetySettings(SafetySetting.builder()
.category("HARM_CATEGORY_DANGEROUS_CONTENT")
.threshold(HarmBlockThreshold.Known.OFF) // OFF disables the content filter
.build())
.build();
}
}
Klocwork reports a JAVA.SV.LLM.SAFETY.DISABLED defect on line 10 because the safety threshold is set to OFF.
Fixed code example 1
import com.google.genai.types.GenerateContentConfig;
import com.google.genai.types.HarmBlockThreshold;
import com.google.genai.types.SafetySetting;
public class Example {
public GenerateContentConfig configure() {
return GenerateContentConfig.builder()
.safetySettings(SafetySetting.builder()
.category("HARM_CATEGORY_DANGEROUS_CONTENT")
.threshold(HarmBlockThreshold.Known.BLOCK_MEDIUM_AND_ABOVE) // real threshold keeps the filter on
.build())
.build();
}
}
In this fixed example, Klocwork no longer reports a JAVA.SV.LLM.SAFETY.DISABLED defect because the safety threshold remains enabled.
External guidance
Security training
Application security training materials provided by Secure Code Warrior.
Extension
This checker cannot be extended through the Klocwork knowledge base.