Skip to content

Securing RAG, tools and agents

Access control across a retrieval index, the confused deputy problem in tool use, and keeping an agent inside its blast radius.

Free on glitchdata intermediate 4 lessons 1 hr 3 min

What you'll learn

  • Describe the attack surface of a retrieval pipeline end to end
  • Enforce per-user access control inside retrieval rather than after it
  • Recognise and prevent confused deputy problems in tool calling
  • Bound an agent's blast radius with budgets, allow-lists and checkpoints

About this course

Retrieval and tool use are where language models stop being a text box and start being part of the system — and where the interesting failures live.

This course covers the attack surface of a retrieval pipeline, carrying permissions into the index, the confused deputy problem that tool calling creates, and how to bound what an autonomous agent can do when something in its context goes wrong.

Before you start

  • Prompt injection and LLM application security, or equivalent experience
  • Familiarity with retrieval-augmented generation

Course content

4 lessons · 1 hr 3 min

  1. 1
    The attack surface of retrieval

    Every stage of a RAG pipeline is somewhere an attacker can write, read or hide.

    Free preview 15 min
  2. 2
    Access control that survives retrieval

    Filter in the query, not in the answer, and keep permissions attached to chunks.

    16 min
  3. 3
    Tools, MCP servers and the confused deputy

    When the model acts with the application's authority instead of the user's.

    16 min
  4. 4
    Keeping an agent inside its blast radius

    Budgets, sandboxes, checkpoints and the question of what one bad turn can cost.

    16 min

What learners say

Sign in and enrol to leave a review.

No reviews yet — be the first once you have worked through it.

More in AI security