Ten distinct tasks · Security and verification
Protect application boundaries
Private data, credentials, permissions, uploads, recovery and audit evidence. Choose a specific task for its worked example, adaptable agent brief and acceptance checks.
10 guides found
Protect private data when using AI: minimize inputs and control destinations
Classify the material, remove information the task does not need and verify the intended service’s data-handling configuration before sharing. A worked example, agent brief, failure checks and acceptance evidence.
Find exposed API keys in an AI project: inspect artifacts and revoke authority
Inspect source, generated browser assets, logs and repository history for privileged credentials. A worked example, agent brief, failure checks and acceptance evidence.
Test user permissions in an AI app: two identities and direct resource requests
Use controlled accounts with different permissions and test direct resource reads and writes. A worked example, agent brief, failure checks and acceptance evidence.
Secure file uploads in an AI-generated app: type, size, ownership and retrieval
Limit accepted files at the receiving boundary and define storage ownership and retrieval access. A worked example, agent brief, failure checks and acceptance evidence.
Rate-limit AI app endpoints: protect costly actions without blocking useful work
Identify expensive or abuse-prone operations and enforce limits at an authoritative boundary. A worked example, agent brief, failure checks and acceptance evidence.
Handle prompt injection in a coding agent: untrusted text cannot grant authority
Treat repository text, webpages and tool outputs as evidence unless they are trusted instructions under the workflow’s policy. A worked example, agent brief, failure checks and acceptance evidence.
Build an account deletion flow with AI: scope, confirmation and retained records
Define what is deleted, what is retained and why before implementing the button. A worked example, agent brief, failure checks and acceptance evidence.
Test backups for an AI-generated app: recovery is the evidence that matters
Define the data and configuration needed for recovery, then restore a controlled backup into an appropriate isolated environment. A worked example, agent brief, failure checks and acceptance evidence.
Review dependencies in an AI-generated project: necessity, provenance and maintenance
Inspect why each new package is needed, where it came from and how it affects the runtime. A worked example, agent brief, failure checks and acceptance evidence.
Design audit logs for an AI application: useful events without private dumps
Record the actor, operation, outcome and correlation reference needed to investigate meaningful actions. A worked example, agent brief, failure checks and acceptance evidence.