Skip to content

Overview

Section 9 · Safety & Security — Secrets, generated-code risk, prompt injection, supply chain, OWASP catalogues, privacy, accountability.

11 lessons in two parts. Part 1: 1: your workflow, secrets, generated code. Part 2: 2: OWASP, agents, privacy, accountability.

By the end of this section you can

  • Threat-model your own workflow, with the agent drawn inside the trust boundary.
  • Keep secrets out of code, git history and prompts, and know the first five minutes after a leak.
  • Review generated code for its specific traps: invented dependencies, insecure defaults, licence risk.
  • Recognise prompt injection, install structural mitigations, and own what you commit.

Safety & Security (Part 1: your workflow, secrets, generated code)

Threat-Modeling Your AI Workflow

intermediate · ~18 min — An agent is a new actor in your workflow. It reads files, runs shell commands, installs packages and calls APIs using credentials issued to you.

Secrets Hygiene

beginner · ~15 min — A leaked key is not a code bug you fix on Friday.

Secure Code Generation

intermediate · ~20 min — Generated code arrives looking finished. It is formatted, it names variables reasonably, and it often runs on the first try.

Prompt Injection And Exfiltration

advanced · ~20 min — Prompt injection is the security problem that does not look like one.

Supply Chain Security

advanced · ~20 min — Your codebase is mostly other people's code. Every dependency, every action your pipeline calls and every base image your build pulls is a package someone else can change without asking you.

Safety & Security (Part 2: OWASP, agents, privacy, accountability)

OWASP LLM Top 10 In Plain English

intermediate · ~20 min — The OWASP LLM Top 10 is the shared vocabulary for "what goes wrong when you put a model inside a product". If you build an AI feature, it is your review checklist.

OWASP Agentic Threats

advanced · ~18 min — An agent is not a chatbot with extra features.

Privacy And Compliance Basics

intermediate · ~20 min — The moment your product handles a real person's name, phone number or payment detail, obligations attach — and AI blurs them, because data leaves your infrastructure in a prompt and returns as text nobody structured.

Human Accountability

beginner · ~12 min — An agent can write a thousand lines in four minutes.

Security Checklists

intermediate · ~15 min — Security advice is easy to read and impossible to remember at the moment it matters — three minutes before you push, with an agent asking whether it can also "tidy up the config".

Security Exercises

advanced · ~25 min — Reading about prompt injection teaches you the vocabulary. Testing whether your agent obeys an injected instruction teaches you whether you have a problem, and it takes about ten minutes.


← 8. MCP · Home · Sidebar · 10. Quality →