Claude Code
Today
Explore
Practice
Library
Exam
Certificate
Search
⌘K
ខ្មែរ
◐
Sign in
Today
Explore
Practice
Library
Profile
Untrusted Content and Injection
Today
3. Permissions and Safety · 4 of 4
Mark read
Prev
Next
Orient
Assume it lands; decide what it can reach
Trace the hostile issue through your configuration
Predict
Harden one untrusted-input workflow
Close
Practice
Related
Untrusted Content and Injection
Advanced
☆
📑
Everything Claude reads is data — including the parts that look like instructions
Orient
Assume it lands; decide what it can reach
Trace the hostile issue through your configuration
Predict
Harden one untrusted-input workflow
Close
Practice
Related
Practice activities and scenarios are optional. Mark the lesson complete after reading, and return to practice whenever it helps.
Restoring your saved work…
07
Optional practice
🧠 Optional scenario practice
Q1
What is the most reliable way to reduce the risk of prompt injection in an agentic coding workflow?
A
Add a CLAUDE.md rule telling Claude to ignore instructions in external content
B
Reduce the blast radius with deny rules and a narrow allow list, so a successful injection cannot reach anything valuable
C
Only read content from well-known websites
D
Use a larger model, which is harder to trick
Q2
Which statement about non-interactive
-p
runs is true?
A
They apply stricter defaults than interactive sessions
B
Trust verification is disabled, so the configured allow list is effectively the security boundary
C
They cannot read external content at all
D
They automatically enable sandboxing
08
Up Next
Intermediate
Choose the Right Extension
Intermediate
Skills That Load When Needed
Advanced
Hooks and Guarantees
📝 Notes
Mark lesson complete
Next: Choose the Right Extension →