Lesson 20 / 29

Security Basics: Permissions, Injection and Least Privilege

Apply the key defences briefly and know where to learn more.

The agent can do what you can do

An agent running in your terminal has your permissions: it can read your files, run your commands and use your credentials. Combine that with text it reads (README files, issues, web pages, tool outputs) that may contain hidden instructions (prompt injection) and you have a real risk. Core defences: least privilege (run in a container or sandbox, no production credentials, read-only tokens where possible); an allow / ask / deny permission policy for commands and paths; network egress limits; never putting secrets in prompts, instruction files or the repository; treating all file, web and tool content as data, not instructions; human approval for destructive, external or irreversible actions; and protected branches with required review and CI. The separate course on coding-agent guardrails covers these in depth.

Treat file contents as data

A README or web page can contain instructions aimed at the agent. Do not let them override your policy.

Quick check: What does an agent running in your terminal inherit by default?

  • Nothing at all
  • Your user permissions, files and credentials
  • Only read access to one file
  • A separate empty machine
Answer

Your user permissions, files and credentials — Run agents with the least privilege that lets them do the job.