AI agent security training
The real risks of autonomous agents: prompt injection, exfiltration via MCP, sandboxing, permissions, security hooks. AI agent red teaming.
Target audienceCISOs, CIOs, DevSecOps, developers, security architects
What you'll be able to do
Identify attack vectors specific to AI agents
Implement sandboxing and permission management mechanisms
Configure security hooks to detect and block malicious behaviour
Conduct a red teaming exercise on an AI agent
Define a security policy for deploying agents in production
Programme
- Day 1, morning
The AI agent threat model
- The 3 attack surfaces: prompt, tools, context
- Direct and indirect prompt injection: live demonstrations
- Injection vectors: web pages, emails, documents, API responses
- Defence techniques: data/instruction separation, validation, human confirmation
- Day 1, afternoon
Exfiltration, sandboxing and permissions
- Exfiltration via agent tools: files, URLs, APIs
- MCP and attack surface: malicious servers, tool poisoning, escalation
- Sandboxing: filesystem, network, process isolation
- Workshop: configuring a secure environment for an agent
- Day 2, morning (optional)
Security hooks and red teaming
- Detection hooks: secrets, suspicious URLs, dangerous commands
- Prevention hooks: block push --force, limit outgoing requests
- Red teaming in pairs: attacking and defending an agent
- Hook bypass: testing protection robustness
- Day 2, afternoon (optional)
Security policy and monitoring
- Writing your organisation's agent security policy
- Production monitoring: what to log, KPIs, alerting
- Incident response: detection, containment, investigation, recovery
- Action plan: the first 5 hardening actions
Practical information
1 to 2 days (7 to 14 hours)
CISOs, CIOs, DevSecOps, developers, security architects
Basic IT security knowledge. Familiarity with AI concepts.
1 to 6 people
30% theory, 70% offensive and defensive workshops on sandbox environments. Each participant leaves with an AI security policy and configured hooks.
Entry-level assessment, red teaming exercises, end-of-training knowledge evaluation.
Colombani.ai, AI developer and cybersecurity expert.
At least 2 weeks between enrolment and the start of training.
Qualiopi-certified provider (training provider registration number 11757549975): OPCO or FIF-PL support can be requested. The decision rests with the funding body, based on your sector, its criteria and its budgets. Colombani.ai prepares the application with you.
Pricing by quotation, charged per group rather than per person, according to the format, group size and level of expertise. OPCO or FIF-PL funding is available. The amount payable after funding is often well below the list price.
Accessibility
This course is accessible to people with disabilities. Contact the disability officer in advance to discuss possible adjustments.
Ulysse Trin, [email protected]
Post-training support
Frequently asked questions
Do I need pentesting skills for this training? +
No, but basic IT security knowledge is needed. The training is progressive: we start with the threat model before moving to red teaming.
Is red teaming done on real agents? +
Yes, on agents configured in a sandbox for the exercise. You attack and defend real agents in a controlled environment.
Does this training cover MCP risks? +
Yes, an entire session is dedicated to MCP risks: malicious servers, tool poisoning, privilege escalation. It's a critical attack vector for agents.
Related courses
Claude Code training: shipping to production
Code with an AI agent, organise your repository, deploy as a team. CLAUDE.md, hooks, subagents, multi-agent workflows. From terminal to production setup in 2 days.
AI compliance training: AI Act & GDPR
Classify AI uses, document transparency and risk controls, and build a roadmap aligned with the revised 2026-2028 AI Act timetable.
Got a project in mind?
Describe your situation. The first 30-minute call is free. Get a frank response within 48 hours.