AI Security Engineer Foundations

Explore the program, earn your certificate, and take your AI security skills to the next level.

Level up your AI skills with Snyk's AI Security Engineer Foundations program. Work through six modules and earn an official badge for each one you complete. Complete all six and receive a certificate of completion that validates your ability to build, ship, and secure AI-powered applications in the real world.

Sessions are designed for builders, engineers, and security practitioners who want to move fast without compromising security in an AI-native development environment.

The six modules

OWASP Top 10 for Agentic Applications OWASP Top 10 for Agentic Applications Addressing Shadow AI Addressing Shadow AI AI Governance & Policy as Code AI Governance & Policy as Code
Securing Agents & MCP Securing Agents & MCP Securing Vibe Coding Securing Vibe Coding AI Pen Testing AI Pen Testing

1. OWASP Top 10 for Agentic Applications

Gain a practical understanding of the key security risks introduced by agentic AI applications. This module explains how risk changes when AI systems can reason, plan, use tools, access memory, interact with other agents, and take actions across business workflows.

By the end of this module you'll be able to:

  • Explain the OWASP Top 10 for Agentic Applications vs. the Web and LLM versions
  • Describe how agentic AI changes security models through goals, tools, memory, identity, permissions, and orchestration
  • Define ten agentic risks, including Agent Goal Hijacking, Tool Misuse, Identity and Privilege Abuse, and Agentic Supply Chain Vulnerabilities
  • Map risks to controls: least privilege, scoped identities, tool allowlisting, approval gates, memory isolation, and audit logging
  • Assess an agent's boundaries — its capabilities, authority, data access, callable tools, and logging/approval requirements

top

2. Addressing Shadow AI

Step into the shoes of the AI Security Engineer to navigate the unexpected things that surface when you look under the hood of your AI posture. This module operates at the intersection of platform security, ML engineering, and threat intelligence.

By the end of this module you'll be able to:

  • Define Shadow AI vs. Shadow IT, and cite current prevalence and cost data
  • Recognize what makes Shadow AI harder to govern than traditional shadow IT
  • Identify common Shadow AI risk scenarios inside an enterprise
  • Define an AI Bill of Materials (AIBOM) and its governance functions
  • Compare an AIBOM against an SBOM across scope, behavior, risk classes, and update cadence
  • Generate an AIBOM using the Snyk CLI and inspect it in the Evo platform

top

3. AI Governance & Policy as Code

This module tackles why most corporate AI policies exist only on paper. It opens by diagnosing the common failure patterns, unenforced wiki policies, review boards too slow to keep up with development, and outright bans that just push AI use underground, before making the case that governance only works when it's built directly into the software pipeline rather than handled through traditional vendor-style approval processes.

From there, the module walks through the practical mechanics of doing this well: identifying the four trust boundaries inside an AI system (data ingestion, external data sources, context construction, and downstream actions) that any real policy needs to address; turning plain-language governance rules into automated checks that run in continuous integration; and stress-testing those rules against ambiguous, real-world edge cases where reasonable teams disagree. It also covers designing a fast, visible exception process so legitimate exceptions don't quietly undermine the policy, and closes with what auditors and regulators actually expect to see, an inventory, a risk assessment, and an enforcement log, tying this back to frameworks like NIST's AI RMF, the EU AI Act, and Gartner's AI TRiSM.

By the end, a learner should come away understanding how to convert an AI governance intent into an enforceable, auditable control rather than a static document, and how to spot the gaps and blind spots that make most current AI policies unenforceable in practice.

top

4. Securing Agents & MCP

How SKILL.md Introduced Malware.

A two-part session covering "ToxicSkills" research on supply-chain threats targeting agent ecosystems, plus active exploitation techniques against Model Context Protocol (MCP) deployments — credential exfiltration via malicious tool descriptions, and arbitrary code execution via insecure servers.

By the end of this module you'll be able to:

  • Explain the Model Context Protocol, why it exists, and its server security fundamentals
  • Articulate why MCP security is urgent in 2026: SDK download scale, agentic IDE adoption, and MCP's placement in a developer's most privileged context
  • Define tool poisoning and the impact of hidden instructions
  • Distinguish malicious MCP servers from vulnerable server code
  • Run MCP-Scan against a local configuration and interpret its findings
  • Run Snyk Code against MCP server source and interpret command-injection and path-traversal findings

top

5. Securing Vibe Coding

In this module, we break down the security implications of vibe coding and share actionable strategies to secure AI-generated code at scale — including Snyk Studio's approach to securing the AI-powered SDLC from code to deployment.

By the end of this module you'll be able to:

  • Define vibe coding and explain how it changes the development process
  • Describe the "Lobster Ecosystem" — agentic AI tools, agent skill registries, and automation frameworks — and its supply-chain attack surface, including agent skill poisoning and slopsquatting
  • Apply a five-layer Secure-by-Design Playbook to vibe-coded projects
  • Identify common AI-generated code vulnerability patterns: disabled row-level security, hardcoded secrets, missing authentication, and client-side security logic
  • Map vulnerabilities to the OWASP Top 10 for LLM Applications
  • Distinguish vibe coding from vibe hacking

top

6. AI Pen Testing

Gain a practical understanding of how to test AI-powered and agentic applications for security weaknesses. This module explains how AI penetration testing goes beyond traditional web and API testing by examining prompts, model behavior, context handling, tool access, memory, permissions, and downstream actions.

By the end of this module you'll be able to:

  • Explain how AI penetration testing differs from traditional application, API, and infrastructure testing
  • Identify AI-specific attack surfaces: prompts, system instructions, RAG pipelines, embeddings, tools, agents, memory, and MCP-connected services
  • Test for common weaknesses: prompt injection, sensitive information disclosure, system prompt leakage, excessive agency, and unsafe output handling
  • Build safe, repeatable test cases without harmful or production-impacting techniques
  • Map findings to remediation: input/output validation, tool allowlisting, scoped tokens, human approval gates, and audit logging
  • Combine AI-specific testing with standard API, authentication, authorization, and dependency testing

top

Badges and the certificate of completion

Every module you pass earns you a verifiable Accredible badge. Complete all six and you'll also earn a certificate of completion — proof that you can build, ship, and secure AI-powered applications in the real world.

top