Skip to content Skip to sidebar Skip to footer

Securing AI Agents Tool Use, Permissions and Boundaries

Securing AI Agents Tool Use, Permissions and Boundaries

Published 10/2026
MP4 | Video: h264, 1920×1080 | Audio: AAC, 44.1 KHz, 2 Ch
Language: English | Duration: 11h 22m | Size: 2.65 GB

Build a hardened AI agent bench: MCP, least-privilege tools, OPA policy, sandboxes, tokens, approvals and audit logs

What you’ll learn
Explain what changes when a model can act, and draw trust zones around the model, loop, tools, memory and identity
Build a local agent bench with Ollama and a small tool-calling model, with every step of the agent loop logged
Write your own MCP server, read exactly what the model sees, and validate tool inputs and outputs against schemas
Replace open-ended tools with narrow ones, confine file paths correctly and split read and write servers
Put an OPA policy decision in front of every tool call, with argument-level rules tested before they ship
Run tools in hardened containers with no network by default, resource limits and throwaway execution
Use short-lived, audience-bound tokens and scoped credentials so an agent never carries more authority than it needs
Keep untrusted content out of instructions with marking, plan-then-execute and a guard model, and block injected actions by policy
Add human approval gates bound to one request, per-user memory isolation, access-controlled retrieval and redaction
Enforce budgets, log every tool call, write detection rules, pin MCP servers, threat model the agent and run a kill-switch drill

Requirements
Comfort with Python and the command line; you can read a short script and run it
A machine that runs Docker; Linux is recommended because one lab uses bubblewrap. No GPU is needed: the labs run on CPU

Description
“This course contains the use of artificial intelligence.”

An AI agent is a language model that can act: it calls tools, reads files, sends requests and remembers what it saw. The moment output becomes action, the security questions change. This course is about the boundaries that keep an agent’s actions within what you intended, built and tested one by one on a local bench you can watch step by step.

You start by building that bench: Ollama in a container bound to localhost, a small tool-calling model chosen for size, speed and licence, and a minimal agent loop in Python that logs every step. From the first tool call you see how the model chooses arguments, including invented ones, and why validation has to start at the tool boundary.

Next you read the Model Context Protocol from the defender’s seat. You write your own MCP server with the Python SDK, list exactly what the model will see, learn why tool annotations are hints rather than controls, and validate both tool inputs and structured results. Least privilege follows: an open-ended shell tool is replaced by narrow functions, file paths are confined correctly, and read and write access are split across separate servers.

Every tool call then passes through one decision point. You run OPA, write Rego policies with argument-level rules for paths, hosts and row limits, wire the agent loop to ask before every call, and test the policies before they ship. Tools run in hardened containers with a read-only filesystem, all capabilities dropped, no network by default and resource limits, and agent-written code runs in throwaway containers. Stronger isolation options are explained conceptually.

Identity gets its own section: whose authority the agent uses, MCP servers as OAuth resource servers, audience-bound tokens, why token passthrough is forbidden and how scoped credentials keep secrets out of prompts. Prompt injection is treated as a boundary problem rather than a filtering problem, with untrusted content marked and kept out of instructions, plan-then-execute, a guard model on CPU, and a policy that blocks the injected action even when the model follows it.

The final sections cover the operational controls: human approval gates bound to one request, per-user memory isolation, retrieval that filters before it retrieves, redaction of secrets and personal data, step and token budgets, rate limits, structured audit logs, OpenTelemetry spans and detection rules. You pin MCP servers and audit client configuration as code, threat model the agent with MAESTRO, map your controls to the OWASP agentic risks and the NIST AI RMF, and finish with a kill-switch drill and a full control check of the finished bench.

Twelve downloadable documents come with the course, including the bench handbook, a threat model workbook, an MCP hardening checklist, a Rego policy guide, a sandbox checklist, a human approval policy, an audit log schema with detection rules and an incident response runbook, plus the complete agent bench as a ZIP. Regulatory dates are taken from primary sources and presented with their status.

Who this course is for
Security engineers who are asked to review or approve AI agents and tool integrations
Developers and platform engineers building agents with MCP servers and tool calling
AppSec and cloud security teams who need practical controls for agentic AI, not just a list of risks

SCRUENHRGTAGFTFERTUYEUSRFEPERMISEDO

you must be registered member to see linkes Register Now

Leave a comment