course

NL/EN
This training is available in Dutch and English.More information

Secure AI Programming

Learn how to securely acquire, configure, and use agentic skills in your AI coding agents.

Not yet scheduled
-No location
-
1 day
895 (excl. VAT)

Description

AI coding agents such as Claude Code, Cursor, and GitHub Copilot are extended through skills: reusable packages of instructions, scripts, and configuration that shape how an agent does its work. That skill layer has become a prime attack surface, ranging from credential-stealing skills and poisoned registries to over-privileged setups and external content that rug-pulls the agent into hostile instructions.

This one-day training covers the four most critical risks from the OWASP Agentic Skills Top 10. Each module pairs theory, grounded in real 2026 incidents, with a hands-on lab in a prepared Claude Code environment, so that what you learn is directly applicable to your daily agentic development the very next morning.

Learning Goals

CheckmarkExplain why agentic skills and MCP tools form a security attack surface
UnderstandLogo InfoSupport
CheckmarkEmploy review techniques to identify malicious code and hidden instructions
ApplyLogo InfoSupport
CheckmarkApply appropriate safeguards to defend against skill supply-chain attacks
ApplyLogo InfoSupport
CheckmarkImplement least privilege and access control for agentic tools and skills
ApplyLogo InfoSupport
For the above learning goals we use Bloom's Taxonomy

Prior Knowledge

  • Basic command-line knowledge
  • Knowledge of CI/CD pipelines and package managers (npm, PyPI, or NuGet)
  • Hands-on experience with at least one agentic coding tool (Claude Code, Cursor, or GitHub Copilot)

Subjects

  • The Agentic Attack Surface
    • Skills versus MCP tools, the lethal trifecta, and a prompt injection primer
  • AST01: Malicious Skills
    • Spotting agentic resources' hidden code and prose payloads
  • AST02: Supply Chain Compromise
    • Registry attacks, and provenance, pinning, and vetted sources for skill acquisition
  • AST03: Over-Privileged Skills
    • How prompt injection weaponises excess permissions, and reducing an agent to least privilege
  • AST05: Untrusted External Instructions
    • Prompt injection through external content, and investigating a poisoned MCP tool

Schedule

All courses can also be conducted within your organization as customized or incompany training.

Our training advisors are happy to help you provide personal advice or find Incompany training within your organization.

"The instructor was clearly very experienced and had a lot of knowledge about the subject."
Mika
  • icon

    Hoge waardering

  • icon

    Praktijkgerichte trainingen

  • icon

    Gecertificeerde trainers

  • icon

    Eigen docenten