Security checklist¶
Use this page when reviewing prompt injection, untrusted retrieval, exfiltration, tool abuse, excessive agency, or unsafe output before shipping a workflow.
Start here¶
- Read the Security lesson for the curriculum framing.
- Open the maintained checklist in the repository path
reference/checklists/security.md(Code tab →reference/checklists/). - Pair the checklist with dated provider guides when a control depends on a provider-native feature.
Related reference¶
- Prompt Doctor for failure diagnosis
- Agents and Tools for tool and approval boundaries
- Provider selection when choosing a stack changes the threat model
This page is a documentation hub. The checklist file under reference/ remains the detailed
working copy so the site does not maintain a second full checklist.