Stage 5 · Advanced
AI Security
Stolen tokens, poisoned tools and the other ways an AI system gets turned against its users.
You'll be able to: Spot the attack paths in an agent stack and close them.
0 of 2 done
-
1
Refresh Token Replay
A stolen refresh token is a working copy of your agent's identity — rotate on every use, revoke the family on reuse, and bind tokens to the client.
-
2
MCP Tool Poisoning
An MCP tool's description is part of the prompt, so a poisoned description can order your agent to leak your secrets.
- Token Rotation done rightAnnounced at the end of an episode in this track. Subscribe to catch it.
- Agent SandboxingAnnounced at the end of an episode in this track. Subscribe to catch it.