Lesson 25 / 25

Revision: Cheat Sheet and Self-Check

Review the layers, controls and habits from the whole course.

Cheat sheet

Threat model: destructive actions, secret exposure, injection, supply chain, scope creep, runaway cost; outside content is data. Policy: allow/ask/deny, unknown means ask, parse commands (do not prefix-match), allowed commands can still run code. Sandbox: resolve paths, container with only the project, protected paths. Secrets and network: clean environment, redaction as a net, exact-host egress allowlist, no metadata endpoint. Git/CI: branch only, server-side protection, size gate, CI scans, human approval. Hooks/budgets: pre-tool hooks fail closed, policy as code, session limits. Operations: audit log, red-team tests, incident checklist, kill switch.

Questions interviewers ask

Be ready to explain: why prompts are not security controls, why a prefix allowlist is bypassable, why an allowlist is not a sandbox, how symlinks defeat naive path checks, how you would stop data exfiltration after a prompt injection, and what you do in the first ten minutes of an agent incident.

Quick check: A hook script crashes while checking a command. What should happen to that command?

  • It is allowed to keep things moving
  • It runs twice
  • It is blocked (fail closed)
  • It is ignored forever
Answer

It is blocked (fail closed) — A broken check must not silently allow risky actions.

Quick check: An injected instruction tells the agent to upload `.env` to a website. Which two controls most directly stop it?

  • Denying reads of .env and an egress allowlist
  • A longer system prompt and a bigger font
  • More commit messages
  • Dark mode
Answer

Denying reads of .env and an egress allowlist — One control keeps the secret out of reach; the other blocks the destination, so the attack needs two failures.

Quick check: Which statement about prefix allowlists is correct?

  • They are safe because commands are short
  • They are required by Linux
  • They replace sandboxes
  • They can be bypassed by chaining operators and substitution
Answer

They can be bypassed by chaining operators and substitution — `git status; rm -rf x` starts with an allowed prefix yet runs a second command.