Kolibrí
🛡️Paid course

Securing LLM Applications

Direct and indirect prompt injection, over-privileged tools and data exfiltration: why there is no fix, and how to shrink the blast radius.

🛡️

Securing LLM Applications

🎓 3 levels📚 12 lessons

1. The Underlying Problem

  • There is no separation between instructions and data
  • Direct and indirect injection: the second is the dangerous one
  • Blast radius: the only variable you control
  • OWASP for LLM as a map, not a certificate

2. Attack Surfaces

  • Tools: where injection becomes an incident
  • Poisoned RAG: when the attacker writes your context
  • Data and system-prompt leakage
  • Cost and availability as an attack vector

3. Defence in Depth

  • Least privilege: the defence that actually works
  • Model output is untrusted input
  • Human in the loop, where it actually matters
  • Testing your own system before someone else does

$10one-time payment

Interested in more courses?

Kolibrí Pro gives you the entire catalog, including new courses as they launch, from $19/mo.

See all plans
See all courses
Securing LLM Applications — Online course with certificate