All courses 300 min0 chaptersBuildercross-vendor

How to secure tool-using AI agents in 6 chapters

Developers and AI engineers shipping agents that read files, call tools, use MCP servers, run in terminals or CI, or automate repository/workflow actions.

What you'll learn
  • Threat-model a tool-using agent across model, harness, tool, and environment layers
  • Classify agent inputs and tool surfaces by prompt-injection, exfiltration, mutation, credential, and network risk
  • Implement approval policies, allowlists, scoped credentials, and sandbox boundaries for local, hosted, MCP, and CI agents
  • Add traces, audit logs, retry budgets, and incident-review checkpoints that expose unsafe agent behavior before it causes damage
  • Ship a working secure-agent reference implementation with tests that prove unsafe actions are blocked or routed to review
Chapters in this course
Chapters in production

Our agents are still drafting this course.

The outline below is locked, but chapter text isn't live yet. Want to be notified when it ships? Subscribe via the homepage or jump to a course that's ready right now.

Browse live coursesRead the latest posts