26. Security Prompting

Use AI to find risks without exposing secrets or creating unsafe instructions.

By Jacques Botte, founder of Toptronic®. Last updated 19 September 2026.

The lesson

Security prompts must avoid sharing passwords, API keys, private certificates, customer data, and undisclosed vulnerabilities with external tools.

Ask for threat models, attack surfaces, data-flow diagrams, input validation checks, dependency risks, and mitigation priorities.

AI security findings are suggestions. A human must verify exploitability and fixes.

A junior security analyst at a software company asks for a threat model of a login flow while leaving all live credentials out of the prompt.

A network team lead at a regional hospital requests a list of attack surfaces for a medical device network without naming any patient.

A security engineer at a payment provider asks for input validation checks on a form and removes customer identifiers before pasting the prompt.

An IT security officer at a municipal council requests a data-flow description of an internal service while excluding server addresses and keys.

A penetration tester at a consultancy writes a prompt about dependency risks and keeps undisclosed findings out of any external tool.

A junior support technician at a logistics firm drafts a prompt about suspicious email patterns and omits the sender addresses involved.

A security architect at a construction group asks for mitigation priorities for a document-sharing service without sharing the actual files.

A fraud analyst at an insurance company requests checks on claim submission patterns and strips all policyholder data from the text.

A junior developer at a game studio asks for a review of session handling and replaces real user tokens with placeholders.

A compliance engineer at an energy utility asks for a threat model of a control network while excluding network diagrams and device passwords.

Check yourself

Question 1: What must not be pasted into external AI tools?
  1. Passwords, API keys, private certificates, and customer data — correct
  2. Public documentation links
  3. General concepts
  4. Empty examples

Answer: Passwords, API keys, private certificates, and customer data

Secrets and sensitive data must be protected.

Question 2: What should a security prompt ask for?
  1. Only slogans
  2. No risks
  3. Only UI colors
  4. Threat model, attack surface, validation checks, dependency risks, mitigations — correct

Answer: Threat model, attack surface, validation checks, dependency risks, mitigations

Security review needs structured risk analysis.

Question 3: How should AI security findings be treated?
  1. As production fixes
  2. As legal sign-off
  3. As suggestions requiring human verification — correct
  4. As automatically proven exploits

Answer: As suggestions requiring human verification

Security findings must be validated.

← Previous lesson · All 91 lessons · Next lesson →

The full course — 91 lessons and 273 quiz questions — ships inside the app. Get TPEE to study it offline.