Skip to contentExploitQuest
LearnAI Code Security

AI Code Security

You are shipping code you did not write. This is how to review it: the bugs models actually produce, the packages they invent that attackers then register, what happens when a model with tools reads attacker-controlled text, and why the confident, idiomatic, plausible version gets reviewed least carefully.

Medium

Not yet reviewed

5 chapters5 lessons5 practice quizzes1 hands-on lab1 examabout 4hup to 450 XP

Before you start

This course expects those first. Nothing is locked — sign in and it will say where you stand.

Start the coursePassing Tests Is the Weakest Signal

What to check first, and why "it passes the tests" is the weakest signal you have.

One-sided — Reviewing is a reading discipline, and the bugs being looked for are attacked in the web security and secure coding courses. Staging an attack here would repeat those rather than close a loop.

1 lesson · 3 min
  1. Passing Tests Is the Weakest Signal3 min
  2. Practice quiz5 questions

Models invent package names. Attackers read the same models and register them.

One-sided — Registering a hallucinated package is an attacker technique, and publishing one is not something this platform will teach. The defensive half — noticing a dependency nobody chose — is the whole chapter.

1 lesson · 3 min
  1. Names That Were Never Real3 min
  2. Practice quiz5 questions

Injection stops being a text problem the moment the reader can act.

One-sided — Taught against a transcript and a simulated tool rather than a live model, deliberately: a lesson whose output changes between two readers cannot be graded. The attack half belongs to the courses that teach injection properly.

1 lesson · 3 min
  1. When the Reader Can Act3 min
  2. Practice quiz5 questions

A context window is a place your secrets can go, and it is not one you control.

One-sided — This is a habit chapter. There is no attack to pair it with — the failure is a secret leaving your control quietly, and the fix is not pasting it.

1 lesson · 3 min
  1. What You Pasted Into the Box3 min
  2. Practice quiz5 questions

Plausible, idiomatic, subtly broken — and reviewed less carefully because it looks good.

One-sided — The subject is a review failure rather than an exploit. Each example's underlying bug is attacked in the course that owns it.

1 lesson · 3 min
  1. Plausible, Idiomatic, Broken3 min
  2. Practice quiz5 questions

Labs

Hands-on challenges for this course. Each one hides a flag you have to find.

  1. The Code That Looked Finedifficulty 3

Exam

Timed, and it issues a credential anyone can verify. Practice quizzes are untimed; this one is not.

  1. AI Code Security Exam8 questions · pass at 70%