Lesson 25 / 25
Revision: Cheat Sheet and Self-Check
Review the layers, controls and habits from the whole course.
Cheat sheet
Threat model: destructive actions, secret exposure, injection, supply chain, scope creep, runaway cost; outside content is data. Policy: allow/ask/deny, unknown means ask, parse commands (do not prefix-match), allowed commands can still run code. Sandbox: resolve paths, container with only the project, protected paths. Secrets and network: clean environment, redaction as a net, exact-host egress allowlist, no metadata endpoint. Git/CI: branch only, server-side protection, size gate, CI scans, human approval. Hooks/budgets: pre-tool hooks fail closed, policy as code, session limits. Operations: audit log, red-team tests, incident checklist, kill switch.
Questions interviewers ask
Be ready to explain: why prompts are not security controls, why a prefix allowlist is bypassable, why an allowlist is not a sandbox, how symlinks defeat naive path checks, how you would stop data exfiltration after a prompt injection, and what you do in the first ten minutes of an agent incident.
Quick check: A hook script crashes while checking a command. What should happen to that command?
- It is allowed to keep things moving
- It runs twice
- It is blocked (fail closed)
- It is ignored forever
Answer
It is blocked (fail closed) — A broken check must not silently allow risky actions.
Quick check: An injected instruction tells the agent to upload `.env` to a website. Which two controls most directly stop it?
- Denying reads of .env and an egress allowlist
- A longer system prompt and a bigger font
- More commit messages
- Dark mode
Answer
Denying reads of .env and an egress allowlist — One control keeps the secret out of reach; the other blocks the destination, so the attack needs two failures.
Quick check: Which statement about prefix allowlists is correct?
- They are safe because commands are short
- They are required by Linux
- They replace sandboxes
- They can be bypassed by chaining operators and substitution
Answer
They can be bypassed by chaining operators and substitution — `git status; rm -rf x` starts with an allowed prefix yet runs a second command.