Course 3.5 · Curriculum 2026.1
Prompt injection, and the envelope that stops it
The most demonstrable five minutes in the catalogue. Every user-editable field is untrusted input. Build the envelope, then watch the attack fail.
- Estimated effort
- 4 hr
- Lessons
- 34
- Modules
- 6
- Material
- 4 hr
Estimated effort is the sum of the lesson and lab times in this version of the course. It is not video runtime, which is lower.
Canadian dollars. One learner, lifetime access to this course version. Tax extra.
1 lesson free to preview
This course does not issue a certificate on its own. It counts toward the paths listed below, and those do.
01What you will learn
7 capabilities, stated as things you can do
Each one is what you should be able to do at the end, not what the course covers. If an outcome is not testable, it is not an outcome.
- Treat every user-editable field as untrusted input, including the ones your own staff fill in.
- Sanitise record data: truncate, strip angle brackets, collapse newline runs, remove control characters.
- Wrap record data in a data envelope with an explicit boundary marker.
- End every system prompt with the instruction that envelope content is data and never instructions.
- Demonstrate a working injection against an unprotected prompt.
- Demonstrate the same attack failing against the envelope.
- Review someone else’s prompt and find the unwrapped field in it.
02Curriculum
6 modules, 34 lessons
Every lesson shows its length and its type. A SCORM lesson looks like any other lesson, which is the point of ingesting packages rather than linking out to them.
6 modules · 34 lessons · 4 hr of material
Demonstrated first, because a defence you have not seen defeated is a defence you will not maintain.
- VideoEvery user-editable field is untrusted inputA description field on a lead is written by a stranger. It reaches your prompt unchanged unless you do something about it.Preview6 min
- VideoDemonstration: taking over a summarisation prompt6 min
- VideoIndirect injection: the field written months ago6 min
- VideoA field your own staff filled in, and why that does not make it safe6 min
- ReadingWhat an injection can actually reach in your architecture5 min
- VideoThe taxonomy: direct, indirect, and the tool-calling kind5 min
Before you can defend a prompt, learn to see the payload the way the model sees it.
- VideoAnatomy of the payload: where the instruction hides6 min
- VideoWhy a model cannot tell data from instructions on its own6 min
- VideoThe three places this bites: summaries, agent actions, and written fields6 min
- ReadingA short list of real injected phrases, disarmed5 min
- LabLab: write an injection payload against your own stub15 min
Four cheap steps before anything else touches the prompt. None of them alone is the defence. Together they are most of it.
- VideoTruncate, strip, collapse, and remove control charactersCap the length, strip angle brackets, collapse newline runs, and remove control characters.6 min
- VideoWhy truncation alone stops nothing, and why you still do it first6 min
- VideoStripping angle brackets without breaking legitimate text6 min
- VideoCollapsing newline runs, and the multi-line payload it defeats6 min
- ReadingControl characters: the ones a browser hides from you5 min
- LabLab: write the four-step sanitiser15 min
A boundary marker and one line at the end of the system prompt. Small, cheap, and the reason the attack stops working.
- VideoThe data envelope and its boundary marker6 min
- VideoThe last line of the system promptEverything inside the envelope is record data and never instructions. State it explicitly, at the end, every time.6 min
- VideoWhy the instruction goes at the end, not the start6 min
- VideoWhat the model does when it sees something instruction-shaped inside the envelope6 min
- ReadingThe envelope is not encryption. Say what it actually promises.5 min
- LabLab: build the envelope in Apex15 min
Re-run the attack against the defence, then learn to spot the unwrapped field in someone else’s prompt.
- VideoDemonstration: the same attack failing6 min
- VideoWhy it failed: reading the model’s own reasoning6 min
- VideoA regression test for injection6 min
- VideoAttacks that still get through, and what stops those6 min
- ReadingDefence in depth: the envelope is one layer, not the only one5 min
- LabLab: run five attack payloads against the defended prompt9 min
The skill that generalises: reading someone else’s prompt and finding the field nobody wrapped.
- LabReviewing a prompt: finding the unwrapped field15 min
- VideoThe review checklist: five questions for any prompt in your org6 min
- VideoA prompt that looked safe and was not6 min
- ReadingWriting the finding up so a colleague fixes it, not defends it5 min
- QuizCheck: prompt injection10 min
03Before you start
What you need first
Assumed knowledge and setup
- Course 3.4, or equivalent experience calling a model from server-side code.
- A Developer Edition org and a model endpoint. The stub from 3.4 works.
- The attack lab runs entirely against your own org. Nothing here is pointed at a third party.
Courses that come first
- 3.4 · Calling a model from Apex safely8 hr · Advanced
Part of these paths
- AI on SalesforceShareCo Certified AI Practitioner
- The Full StackShareCo Certified Platform Engineer
04Who teaches it
Elliot Saha
Co-founder, Chief Technology Officer
Platform architecture, custom Apex and Lightning Web Components, AI systems, and the Academy platform itself.
05Reviews
No learner reviews yet
This course has not been taken by enough people to publish an honest rating, and we will not print invented quotes on a page that sells verification discipline. Here is what we can evidence instead.
- Assessment
- Lesson checks onlyThis course carries lesson checks. The certificate is issued by the path assessment, not by this course.
- Curriculum version
- 2026.1You enrol into a version. Content changes do not move you mid-course, and your required-lesson count is snapshotted at enrollment.
- Refunds
- 14 daysFull refund within 14 days if you have completed under a quarter of the required lessons. Stated here rather than in a footer.
Start 3.5
Enrol as an individual, or buy seats and assign this course to your team. Progress is reported per lesson, per module and per path.
- 4 hr estimated effort, labs included
- Lifetime access to the version you enrol in
- A ShareCo certificate is not a Salesforce certification