An agent turns a model’s mistakes into actions. Everything in the previous topics applies, and five things are added: threats specific to systems that plan and remember, an identity model for software that acts on someone’s behalf, architectures that stay safe when the model is fooled, containment for code the model writes, and security for the tools it is given.
| # | Lesson | The question it answers |
|---|---|---|
| 01 | Agent Threats | What can go wrong that could not go wrong with a chatbot? |
| 02 | Identity and Authorization | Who is an agent, whose authority does it carry, and how is that scoped? |
| 03 | Architectural Defenses | Which designs resist prompt injection by construction? |
| 04 | Sandboxing and Egress | How is model-written code contained, and how is the way out closed? |
| 05 | MCP and Tool Security | How do I trust, expose and monitor tools and MCP servers? |
The design-side companion is Designing Agentic Systems.