← AI Security and Guardrails That Hold Up

Lesson 1 of 10

The threat model for an LLM feature

Lesson 1 of 10 · AI Security and Guardrails That Hold Up

In this lesson. Prompt injection, data leak, and tool abuse.

What you will learn

  • Injection
  • Leak
  • Tool abuse

Walkthrough

You will write a threat model for one feature. If you cannot name the attacker goal, you cannot design a guardrail. This is lesson one on purpose.

Work through the ideas in order. After each point, pause and connect it to a task you already do — a document, a workflow, or a feature you own. The goal of AI Security and Guardrails That Hold Up is usable skill, not a pile of notes.

If something is unclear, rewrite it in your own words before you continue. Teaching the step back to yourself is the fastest way to see gaps.

Practice

Write a one-page threat model for one feature.

Keep the first attempt small. A finished example you can reuse beats a perfect plan you never run.

Check your understanding

  • Can you explain the goal of this lesson in one sentence to a teammate?
  • Where would you apply “Injection” in your own work this week?
  • What would you change on a second pass of the practice?

Next. Continue to the following lesson when the practice has a real artifact, even a rough one.