Curriculum
Module 09
Untrusted input in a loop
The security model that changes once the model can act: prompt injection through tools, the lethal trifecta, OWASP's LLM Top 10, and real defences.
4 lessons · 10 videos · 4h 20m- 09.01
Prompt injection when the agent can act
Trace how text in a fetched page becomes an action your agent takes.
- 09.02
Private data, untrusted content, and a way out
Identify the three properties that together make exfiltration possible, and break one.
- 09.03
The OWASP LLM Top 10, against your agent
Walk your own agent against the list and say where it stands on each.
- 09.04
Defences that survive contact
Rank the real mitigations and say why prompt-level pleading is not one.