Agent security
Prompt injection
Understand how untrusted content can influence model behavior.
Lesson overview
Prompt injection
Treat documents, webpages, emails, and tool results as untrusted data. An instruction inside retrieved content should not automatically become an instruction for the agent.
Reduce blast radius with capability restrictions, authorization, validation, and approval.
Learning path
Theory → Example → Code → Practice → Quiz → Challenge → Completion
Step 1
Theory
Prompt injection
Treat documents, webpages, emails, and tool results as untrusted data. An instruction inside retrieved content should not automatically become an instruction for the agent.
Reduce blast radius with capability restrictions, authorization, validation, and approval.
Step 2
Example
Example
Apply Prompt injection to a realistic production scenario and trace the decision step by step.
Step 3
Code
Code
Add implementation notes or a runnable example for this concept.
Step 4
Practice
Practice
Write down the inputs, expected output, constraints, and one failure case for Prompt injection.
Step 5
Quiz
Quiz coming soon.
Step 6
Challenge
Challenge
Design a production-ready solution for Prompt injection and explain one important trade-off.
Complete every stage
Work through every step in order, then the lesson will be marked complete.
Each chapter and subtopic has its own public URL under /ai-agent.