UprootSecurityUprootSecurity

Curriculum · Phase 7 · Module 7.5

Agentic AI, RAG Security + Red Teaming

The last and hardest setting: AI that plans and chains tool calls on its own, retrieval that pulls data into the context at query time, and the red-teaming practice that tests it all. This module covers the agentic threat model — excessive agency, tool misuse, runaway loops, goal and memory manipulation — plus MCP security and tool sandboxing; RAG access controls (retrieval filtered by the caller's permissions, provenance, corpus poisoning); and AI red-teaming basics. It ties every earlier thread together: prompt injection becomes tool actions, access control becomes what keeps an agent contained, governance becomes what you must prove. You finish by designing the security controls for an agentic AI assistant — a posture and guardrails for each thing it can do.

75 min

·

4 lessons

·

+50 pts

Article

The Agentic AI Threat Model, MCP Security, and Tool Sandboxing

25 min

+10 pts

Article

RAG Access Controls and AI Red Teaming

15 min

+10 pts

Video

Watch: An Agent Contained by Its Controls

10 min

+10 pts

Exercise

Design Security Controls for an Agentic AI Assistant

25 min

+20 pts

Agentic AI, RAG Security + Red Teaming — UprootSecurity Bootcamp