Kolibrí
🛡️Paid course

Securing LLM Applications

Direct and indirect prompt injection, over-privileged tools and data exfiltration: why there is no fix, and how to shrink the blast radius.

🛡️

Securing LLM Applications

🎓 3 levels📚 12 lessons

1. The Underlying Problem

  • •There is no separation between instructions and data
  • •Direct and indirect injection: the second is the dangerous one
  • •Blast radius: the only variable you control
  • •OWASP for LLM as a map, not a certificate

2. Attack Surfaces

  • •Tools: where injection becomes an incident
  • •Poisoned RAG: when the attacker writes your context
  • •Data and system-prompt leakage
  • •Cost and availability as an attack vector

3. Defence in Depth

  • •Least privilege: the defence that actually works
  • •Model output is untrusted input
  • •Human in the loop, where it actually matters
  • •Testing your own system before someone else does

$10one-time payment

Interested in more courses?

Kolibrí Pro gives you the entire catalog, including new courses as they launch, from $19/mo.

See all plans →
← See all courses
Securing LLM Applications — Online course with certificate