PTENES
Skip to content
TRACK 4

🕳️ What almost no one tells you

Hidden instructions in emails and PDFs, passwords in the wrong place, extensions that inherit your permissions, spending with no cap, and too much customer data. The risks below the surface—and how to close each door.

3
Modules
18
Topics
~1h40
Duration
Practical
Level
0 of 180%
responds 🧪 hidden instructions 🗝️ secrets 🧩 extensions 💸 spending without a limit 👥 customer data what you can see what sinks

Trail map

Detailed content

4.1~35 min

🧪 Hidden instructions

How outside text gives the agent instructions, the rhyme test to see this safely, and the safeguards that hold it back.

0 of 60%
What it is:

An instruction placed inside an email, PDF, or website that the agent reads and follows. Technical name: prompt injection.

Why learn:

Whoever writes the text ends up controlling the agent—without breaking into anything, just by sending an email.

Key concepts:

Hidden instructions, outside content, invisible text, change of ownership.

What it is:

Email, PDF, web page, spreadsheet comment, résumé, and invoice: everything the agent reads as part of its work.

Why learn:

You can’t stop it from reading; you can control what it can do after it reads.

Key concepts:

Front door, attachment, navigation, sources × tools.

What it is:

A one-line message from you with a hidden line asking it to "reply in rhyme," tested in two rounds: without a rule and with a rule.

Why learn:

Seeing the chat itself obey is more convincing than any explanation—and there's no risk.

Key concepts:

Rhyme test, new conversation, no connectors, two rounds.

What it is:

To the model, your instructions and the email from outside arrive as one continuous stream of text, with no label showing who owns what.

Why learn:

Explains why no written rule eliminates risk—and why approval is still necessary.

Key concepts:

Single queue, no labels, trained to obey, reduces but does not eliminate risk.

What it is:

Read ≠ act, few tools enabled, be wary of urgency from outside and get approval before sending.

Why learn:

No single safeguard solves everything. Layered together, the last one catches what the others let through.

Key concepts:

Read ≠ act, fewer tools, urgency becomes a question, approval.

What it is:

A ready-to-use block for the agent's fixed instructions: outside content is information; only you can give instructions.

Why learn:

It's the first and cheapest barrier — as long as you know its honest limits.

Key concepts:

Fixed instructions, warn instead of obeying, honest limits.

View Full
4.2~30 min

🗝️ Passwords and extensions

Secrets, the key file the agent can see, extensions that inherit your permissions, and the leak checklist.

0 of 60%
What it is:

Everything that proves to a system that "it's me." This includes the API key — the password to the door between programs.

Why learn:

Whoever has the secret gets in as you. The system doesn't verify the person, only the key.

Key concepts:

Secret, API, API key, token.

What it is:

The keys are usually stored in a configuration file, such as .env, in the folder the agent can access.

Why learn:

Folder access means access to everything inside it—including keys, if nobody separates them.

Key concepts:

.env, folder access, vault, printing = data leak.

What it is:

You don’t paste secrets into the chat, and the agent doesn’t show secrets on screen. Ready-to-use rule for the instructions.

Why learn:

The history stores everything that goes in. A secret pasted into the chat ends up living in the chat.

Key concepts:

History, don’t paste, don’t print, [SECRET HIDDEN].

What it is:

Other people’s programs that install in the browser, chat, or agent and inherit whatever permissions it has.

Why learn:

Installing it is like hiring a stranger to work inside your office.

Key concepts:

Extension, its permissions, asks × promises, update.

What it is:

Three questions in two minutes: who published it, what it asks for, and whether you really need it.

Why learn:

It prevents most problems—and many extensions do what the chat can already do without installing anything.

Key concepts:

Who published it, list of permissions, do I really need this, test profile.

What it is:

Revoke, create a new one, replace it wherever it was used, and check spending—with a checklist ready to fill out today.

Why learn:

Deleting the message doesn’t solve it. On the day of a leak, you don’t want to be searching for where the button is.

Key concepts:

Revoke, create a new key, replace it, check spending.

View Full
4.3~35 min

💸 Spending, isolation, and LGPD

Spending and effort limits, a sandbox for the agent, LGPD on one page, and the four-gate checklist.

0 of 60%
What it is:

Monthly account limit, usage alert, and a virtual card just for AI services.

Why learn:

An agent in a loop spends money with every pass. Without a cap, you find out on the bill.

Key concepts:

Spending limit, alert, virtual card, worst-case scenario.

What it is:

Time, attempt, message, and machine limits—and what the agent does when it hits them.

Why learn:

A loop without a cap uses money, time, and computing resources all at once. The fix is usually one line.

Key concepts:

Loop, maximum time, attempts, stop and notify.

What it is:

Restricted folder, separate account, or sandbox (sandbox/container): an enclosed space for the agent to work in.

Why learn:

If it makes a mistake or gets tricked, the damage stays inside—away from your bank account and your keys.

Key concepts:

Sandbox, container, restricted folder, copy.

What it is:

Personal data, sensitive data, legal basis, purpose, necessity, and data subject rights — applied to the agent.

Why learn:

The law applies just the same when an AI reads the spreadsheet. You remain responsible.

Key concepts:

Personal data, sensitive data, legal basis, purpose.

What it is:

Remove columns the task doesn’t use and replace names with codes before the data reaches the agent.

Why learn:

The agent works the same way, and anything that leaks is worth much less.

Key concepts:

Minimize, anonymize, key table, before and not after.

What it is:

One checklist with the four gates for the agent you chose at the start of the course.

Why learn:

Combines Track 4 into a single document and feeds the "security" block in the Track 5 spreadsheet.

Key concepts:

Four doors, an owner, a date, an open door = agent turned off.

View Full
← Previous trail: Control the system Next track: Own the outcome →