Skip to content

Prompt injection and LLM application security

How injection works, why filtering fails, and the design patterns that actually contain it.

Free on glitchdata intermediate 4 lessons 59 min

What you'll learn

  • Explain why prompt injection cannot be filtered away
  • Trace an indirect injection from a document to a tool call
  • Choose defences that constrain capability rather than wording
  • Handle model output safely in HTML, SQL, shells and URLs

About this course

Prompt injection is the defining vulnerability of language model applications, and the one most commonly answered with defences that do not work.

This course covers the mechanism, the indirect variants that reach systems through documents and web pages, the defences worth deploying, and how to handle model output without inheriting an older class of bug.

Before you start

  • Experience building an application that calls a language model

Course content

4 lessons · 59 min

  1. 1
    How prompt injection actually works

    One stream of text, no separation of instruction from data, and what follows.

    Free preview 15 min
  2. 2
    Indirect injection: the page, the PDF, the email

    Following an attack from a planted document to a tool call nobody authorised.

    16 min
  3. 3
    Defences that hold, and those that do not

    Ranking the common mitigations by how much they actually change the system's permissions.

    15 min
  4. 4
    Handling model output safely

    The model is an untrusted string source; treat its output like any other user input.

    13 min

What learners say

Sign in and enrol to leave a review.

No reviews yet — be the first once you have worked through it.

More in AI security

AI security intermediate

Securing RAG, tools and agents

Access control across a retrieval index, the confused deputy problem in tool use, and keeping an agent inside its blast radius.

4 lessons 1 hr 3 min Free