Skip to content
Academy
Agentforce and AIAdvanced

Course 3.5 · Curriculum 2026.1

Prompt injection, and the envelope that stops it

The most demonstrable five minutes in the catalogue. Every user-editable field is untrusted input. Build the envelope, then watch the attack fail.

Estimated effort
4 hr
Lessons
34
Modules
6
Material
4 hr

Estimated effort is the sum of the lesson and lab times in this version of the course. It is not video runtime, which is lower.

$399

Canadian dollars. One learner, lifetime access to this course version. Tax extra.

1 lesson free to preview

This course does not issue a certificate on its own. It counts toward the paths listed below, and those do.

01What you will learn

7 capabilities, stated as things you can do

Each one is what you should be able to do at the end, not what the course covers. If an outcome is not testable, it is not an outcome.

  1. Treat every user-editable field as untrusted input, including the ones your own staff fill in.
  2. Sanitise record data: truncate, strip angle brackets, collapse newline runs, remove control characters.
  3. Wrap record data in a data envelope with an explicit boundary marker.
  4. End every system prompt with the instruction that envelope content is data and never instructions.
  5. Demonstrate a working injection against an unprotected prompt.
  6. Demonstrate the same attack failing against the envelope.
  7. Review someone else’s prompt and find the unwrapped field in it.

02Curriculum

6 modules, 34 lessons

Every lesson shows its length and its type. A SCORM lesson looks like any other lesson, which is the point of ingesting packages rather than linking out to them.

6 modules · 34 lessons · 4 hr of material

Demonstrated first, because a defence you have not seen defeated is a defence you will not maintain.

  1. VideoEvery user-editable field is untrusted inputA description field on a lead is written by a stranger. It reaches your prompt unchanged unless you do something about it.Preview6 min
  2. VideoDemonstration: taking over a summarisation prompt6 min
  3. VideoIndirect injection: the field written months ago6 min
  4. VideoA field your own staff filled in, and why that does not make it safe6 min
  5. ReadingWhat an injection can actually reach in your architecture5 min
  6. VideoThe taxonomy: direct, indirect, and the tool-calling kind5 min

03Before you start

What you need first

Assumed knowledge and setup

  • Course 3.4, or equivalent experience calling a model from server-side code.
  • A Developer Edition org and a model endpoint. The stub from 3.4 works.
  • The attack lab runs entirely against your own org. Nothing here is pointed at a third party.

Courses that come first

Part of these paths

04Who teaches it

Elliot Saha

Co-founder, Chief Technology Officer

Platform architecture, custom Apex and Lightning Web Components, AI systems, and the Academy platform itself.

Full background

05Reviews

No learner reviews yet

This course has not been taken by enough people to publish an honest rating, and we will not print invented quotes on a page that sells verification discipline. Here is what we can evidence instead.

Assessment
Lesson checks onlyThis course carries lesson checks. The certificate is issued by the path assessment, not by this course.
Curriculum version
2026.1You enrol into a version. Content changes do not move you mid-course, and your required-lesson count is snapshotted at enrollment.
Refunds
14 daysFull refund within 14 days if you have completed under a quarter of the required lessons. Stated here rather than in a footer.
Enrol

Start 3.5

Enrol as an individual, or buy seats and assign this course to your team. Progress is reported per lesson, per module and per path.

  • 4 hr estimated effort, labs included
  • Lifetime access to the version you enrol in
  • A ShareCo certificate is not a Salesforce certification