Skip to content
Compliance

AI agent security training

The real risks of autonomous agents: prompt injection, exfiltration via MCP, sandboxing, permissions, security hooks. AI agent red teaming.

1 to 2 days (7 to 14 hours) Eligible for OPCO / FIF-PL funding

Target audienceCISOs, CIOs, DevSecOps, developers, security architects

What you'll be able to do

Identify attack vectors specific to AI agents

Implement sandboxing and permission management mechanisms

Configure security hooks to detect and block malicious behaviour

Conduct a red teaming exercise on an AI agent

Define a security policy for deploying agents in production

Programme

  1. Day 1, morning

    The AI agent threat model

    • The 3 attack surfaces: prompt, tools, context
    • Direct and indirect prompt injection: live demonstrations
    • Injection vectors: web pages, emails, documents, API responses
    • Defence techniques: data/instruction separation, validation, human confirmation
  2. Day 1, afternoon

    Exfiltration, sandboxing and permissions

    • Exfiltration via agent tools: files, URLs, APIs
    • MCP and attack surface: malicious servers, tool poisoning, escalation
    • Sandboxing: filesystem, network, process isolation
    • Workshop: configuring a secure environment for an agent
  3. Day 2, morning (optional)

    Security hooks and red teaming

    • Detection hooks: secrets, suspicious URLs, dangerous commands
    • Prevention hooks: block push --force, limit outgoing requests
    • Red teaming in pairs: attacking and defending an agent
    • Hook bypass: testing protection robustness
  4. Day 2, afternoon (optional)

    Security policy and monitoring

    • Writing your organisation's agent security policy
    • Production monitoring: what to log, KPIs, alerting
    • Incident response: detection, containment, investigation, recovery
    • Action plan: the first 5 hardening actions

Practical information

Duration

1 to 2 days (7 to 14 hours)

Target audience

CISOs, CIOs, DevSecOps, developers, security architects

Prerequisites

Basic IT security knowledge. Familiarity with AI concepts.

Group size

1 to 6 people

Teaching approach

30% theory, 70% offensive and defensive workshops on sandbox environments. Each participant leaves with an AI security policy and configured hooks.

Assessment

Entry-level assessment, red teaming exercises, end-of-training knowledge evaluation.

Trainer

Colombani.ai, AI developer and cybersecurity expert.

Booking lead time

At least 2 weeks between enrolment and the start of training.

Funding

Qualiopi-certified provider (training provider registration number 11757549975): OPCO or FIF-PL support can be requested. The decision rests with the funding body, based on your sector, its criteria and its budgets. Colombani.ai prepares the application with you.

Pricing by quotation, charged per group rather than per person, according to the format, group size and level of expertise. OPCO or FIF-PL funding is available. The amount payable after funding is often well below the list price.

Discuss this course (30 min) OPCO funding is discussed during the call.

Accessibility

This course is accessible to people with disabilities. Contact the disability officer in advance to discuss possible adjustments.

Ulysse Trin, [email protected]

Post-training support

Red teaming report written during the exercise
Agent security policy (template + completed version)
Suite of configured and tested security hooks
Security checklist for agent deployment
Security support for 30 days

Frequently asked questions

Do I need pentesting skills for this training? +

No, but basic IT security knowledge is needed. The training is progressive: we start with the threat model before moving to red teaming.

Is red teaming done on real agents? +

Yes, on agents configured in a sandbox for the exercise. You attack and defend real agents in a controlled environment.

Does this training cover MCP risks? +

Yes, an entire session is dedicated to MCP risks: malicious servers, tool poisoning, privilege escalation. It's a critical attack vector for agents.

Got a project in mind?

Describe your situation. The first 30-minute call is free. Get a frank response within 48 hours.