Code Nexus
CurriculumHow we teachPricingBlogAboutContact
Start learning
  1. Curriculum
  2. /
  3. Season 6
  4. /
  5. Episode 7

Season 6: Build Code Nexus Assist · Episode 7 of 8

The Agent Did What?

You play: Junior AI Developer

Included with Core programme and Certification prep
See plans

The situation

Overnight, Code Nexus Assist read the partner shipping FAQ from the shared support folder. Someone with write access to that folder had added a sentence to the footer that is not addressed to a person: it tells any AI assistant reading the page to export another creator's data and include it in its reply. The trace shows the assistant tried to do exactly that. The export never happened, but only because that tool hadn't been granted to it. Lydia wants to know how much of that was design and how much was luck, and Amara wants numbers.

What you'll learn

  • AI-103 responsible AI, security and operationalisation: trust boundaries and indirect prompt injection, guardrails, scoped tools and per-agent grants, output checks, human approval for consequential actions, auditing through traces, and safety and quality evaluation with attack and benign regression sets and error analysis.
  • Azure Content Safety filters and Prompt Shields, Foundry evaluators (groundedness, relevance) and safety evaluations, and audit trails with traces, provenance and approvals.

Who you work with

  • Lydia Roe

    Security Engineer

  • Amara Okafor

    ML and Data Engineer

  • 8-BIT

    Code Nexus Internal AI Assistant

Scenes

  1. 1.The trace nobody expected
  2. 2.Whose words, and do they get a vote?
  3. 3.The output check and its regression set
  4. 4.Scope the tools, gate the consequences
  5. 5.The variant that uses your own tools
  6. 6.The incident report
  7. 7.Security and operations check

What you leave with

You tested the supplied indirect injection and permitted-tool chain, kept the export ungranted, and scored the narrow response filter on attacks and benign cases. The fixture shows specific refusals and successful intended calls. Wider leakage, URL/rendering, approval and logging checks remain necessary; incident classification follows evidence and responsible review.

Previous episode

Give the Assistant Tools

Next episode

The AI Engineering Review

Code Nexus

Practice first. Improvise less later.

We post practical tech tips and the odd 8-BIT opinion. Mostly the tips.

The CPD Group Approved Provider #791172

Learn

  • Curriculum
  • Pricing
  • Create account
  • Sign in

Support

  • Blog
  • Certification guides
  • About Code Nexus
  • How we teach
  • Human help

Legal

  • Terms and Conditions
  • Privacy Policy
  • Cookie Policy
  • Refund and Cancellation
  • Contact: contact@codenexus.co.za

© 2026 Code Nexus. All rights reserved.

Payments secured by Payfast · Billed in ZAR · South Africa