Automate and code with AI, safely

Complete plan

Five short modules for operations teams, power users and IT: choose what is worth automating, pick between a script, an AI and an agent, code with an AI assistant without secrets or dubious libraries, give an agent the fewest rights possible, and recognise prompt injection.

  • 12 min
  • 5 modules
  • 15-question check
  • English · Français
  • Attestation

You will be able to

  • Spot a task worth automating: frequent, with clear rules, where a mistake can be put right
  • Tell apart a rule-based script, an AI (language model) and an agent
  • Keep secrets (keys, passwords, tokens) out of the code and out of the conversation with the assistant, and revoke any exposed secret
  • Understand that an agent connected with your account acts with all your rights, and spot the three excesses: too many tools, too many rights, too much autonomy
  • Recognise prompt injection: hidden instructions in a document, an email or a web page that an AI reads

Programme

5 modules · 12 min
  1. What is worth automating 2 min
    • Spot a task worth automating: frequent, with clear rules, where a mistake can be put right
    • Keep a human check when a mistake is costly, and leave rare or ever-changing work by hand
    • Before you start: measure the time spent, plan for exceptions, name an owner
  2. Script, AI or agent? 2 min
    • Tell apart a rule-based script, an AI (language model) and an agent
    • Choose written rules when they are clear, and AI only for free text, with a check
    • Use an agent only with the fewest rights possible, a human approval before any irreversible action, and a log
  3. Coding with AI, safely 3 min
    • Keep secrets (keys, passwords, tokens) out of the code and out of the conversation with the assistant, and revoke any exposed secret
    • Check every library the AI suggests before installing it: it exists, it is well known and allowed
    • Have the code reviewed and tested before production, and name an owner who maintains it
  4. An agent with the fewest rights possible 2 min
    • Understand that an agent connected with your account acts with all your rights, and spot the three excesses: too many tools, too many rights, too much autonomy
    • Give an agent its own identity, read-only by default, only the access it needs, and test it first without real data
    • Have a human approve any irreversible action (pay, delete, send outside, change rights), log every action, name an owner and plan an immediate stop
  5. Prompt injection in one picture 2 min
    • Recognise prompt injection: hidden instructions in a document, an email or a web page that an AI reads
    • When an AI pushes you to click, sign in again, pay or send, check at the source, and report any behaviour you did not ask for
    • When building an assistant or an agent: treat all outside content as untrusted, and let nothing go out without human approval
  6. Knowledge check

    15 questions, pass mark 80 %. Explanations after each answer; you can try again.

  7. Attestation

    One per person, with the date, the score and the frameworks covered — anyone can check it online with its code.

Version 1 · updated October 6, 2026