When retrieved text becomes an instruction
A closer look at indirect prompt injection, the RAG trust boundary, and why retrieved content should never inherit authority.
Explore the attack surface where language becomes logic. Prompt injection, retrieval boundaries, and practical defenses.
A closer look at indirect prompt injection, the RAG trust boundary, and why retrieved content should never inherit authority.
Understand direct and indirect prompt injection through a workplace example, practical defenses, and a safe trust-boundary exercise.
Follow private data through an AI assistant, distinguish training from retrieval, and practice checking who may see each record.
Learn how models, packages, adapters, and providers enter an AI system, and how to review their origin before trusting them.
Distinguish poisoned training data, tampered models, and corrupted retrieval sources, then practice tracing a false policy back to its origin.
Understand all ten OWASP LLM risks in the 2025 edition through plain-language examples, first defenses, and a small design exercise.
Follow a harmless-looking document into an AI assistant and learn where outside content can become an unauthorized instruction.