← All drillsPrompt Injection & Data Leakage
What you'll be able to do- ✓Tell direct prompt injection apart from indirect, and explain why retrieved content is untrusted input
- ✓Name all four surfaces where data leakage actually happens, not just "the model said something wrong"
- ✓Trace a real attack path hop by hop, from an attacker-controlled document to a customer-facing answer
- ✓Write a security memo mapping each mitigation to the specific point in the pipeline it breaks
Catch a RAG or agent architecture that treats retrieved content as safe context before a hostile document proves it isn't.
⌁ The security or trust-and-safety review that happens right before a RAG/agent system connects to any data source the team doesn't fully control.
Start this internshipCreate an account to unlock the 5 sections, the workbench, and AskThili.
BeginSections
1. Prompt Injection & Data Leakage
🔒 locked2. The Document Is Attacker-Controlled
🔒 locked3. Where Leakage Actually Happens
🔒 lockedDig deeper
🔗The security risk memo template (template pack)
codePart of these learning paths
I'm a leader and I want to evaluate and govern AI investments in my organization
View path →