Security
အဓိက ဦးတည်ချက်SAST/SCA၊ dependencies နဲ့ secret-leak အားနည်းချက်များ။ Prompt injection နဲ့ agent တွေမှာ သီးသန့်ကြုံရတဲ့ attack surfaces များ။ Agent အကူအညီနဲ့ vulnerability တွေကို စစ်ဆေးခွဲခြားခြင်း (triage) နဲ့ ဖြေရှင်းခြင်း (remediation)။
လက်တွေ့ တည်ဆောက်ရန်Threat model တစ်ခု၊ CI အတွင်း SAST / SCA / secret scans များ ထည့်သွင်းခြင်းနဲ့ prompt-injection စမ်းသပ်မှုတစ်ခု ပြုလုပ်ရပါမယ်။
အဓိက လေ့လာစရာများ (Core)≈ 3 h 50 min
- ခြိမ်းခြောက်မှု စာရင်းများ60 minOWASP MCP Top 10 & OWASP Top 10 for LLM Applications
- Embrace The RedGitHub Copilot: Remote Code Execution via Prompt Injection (CVE-2025-53773)15 min
Coding agent တစ်ခုကို အစအဆုံး တိုက်ခိုက်ပြထားတဲ့ attack chain လက်တွေ့ ဖြစ်ရပ်။
- Video · Isaac Evans of [Semgrep](https://semgrep.dev/docs/)When AI Writes Code: Rethinking App Security45 min
AI ရေးတဲ့ Code တွေမှာ ပါလာတတ်တဲ့ အားနည်းချက်များ၊ SAST၊ security assistants၊ feedback loops နဲ့ coding agents တွေကြောင့် ဖြစ်လာတဲ့ အန္တရာယ်များ။
- SemgrepFinding vulnerabilities in modern web apps using Claude Code and OpenAI Codex20 min
Agent အကူအညီနဲ့ triage ပြုလုပ်ပုံ လက်တွေ့။
- Fouad Matin of OpenAISafety and Security for Code-Executing Agents14 min
Remote code execution၊ prompt injection၊ ဒေတာ ခိုးထုတ်မှု (exfiltration)၊ containers၊ network ကန့်သတ်ချက်များ၊ approvals နဲ့ OS-level sandboxing။
- PortSwigger [Web Security Academy](https://portswigger.net/web-security) ≈ 60 minWeb LLM attacks labs
Indirect prompt injection ပါဝင်တဲ့ လက်တွေ့ lab 2 ခုကို စမ်းသပ်ပါ။
Tools and References
- Scanners. SAST အတွက် Semgrep သို့မဟုတ် CodeQL၊ secrets အတွက်
gitleaks၊ dependencies/SCA အတွက်OSV-Scanner။ (Build မှာ ဒီ 3 မျိုးစလုံး ထည့်သွင်းရပါမယ်)။ - Sandboxing & Rules. Anthropic ရဲ့ sandboxing လမ်းညွှန်နဲ့
claude-code-security-reviewGitHub Action။ - OWASP စာတမ်းများ. MCP Tool Poisoning၊ Agentic AI Threats and Mitigations နဲ့ OWASP GenAI Security Project။ Invariant Labs ရဲ့ မူရင်း ထုတ်ပြန်ချက်မှာ MCP Security Notification: Tool Poisoning Attacks ဖြစ်ပါတယ်။
- စာအုပ်. Adam Shostack ရဲ့ Threat Modeling: Designing for Security — ပထမအကြိမ် ထုတ်ဝေမှုကို သုံးပါ၊ AI ကမ္ဘာအတွက် အမည်ပြောင်းထားတဲ့ second edition ကိုတော့ 2027 ဖေဖော်ဝါရီမှာ ထွက်ရှိမယ်လို့ ကြေညာထားပါတယ်။
အပိုဆောင်း Video များ
- Video38 minWhy and How You Need to Sandbox AI-Generated CodeHarshil Agrawal of Cloudflare
capabilities, secrets, networking, cleanup, isolation surfaces နဲ့ indirect prompt injection အကြောင်း။
- Video12 minWeb Security Academy series introductionRana Khalil
PortSwigger labs အတွက် အထောက်အကူပြု Video။
လက်တွေ့ တည်ဆောက်ရန် (Build)
Agent workflow တစ်ခုလုံးကို threat-model ရေးဆွဲပါ - User input၊ repo အချက်အလက်များ၊ ဆွဲယူလာတဲ့ web pages၊ tools၊ credentials၊ MCP servers၊ ထွက်လာတဲ့ commands၊ logs နဲ့ deployment အထိ အကုန်ပါဝင်ရပါမယ်။
Least privilege (အနည်းဆုံး လုပ်ပိုင်ခွင့်ပေးခြင်း)၊ စိတ်ချရတဲ့ allowlist များ၊ secrets တွေကို သီးခြားခွဲထားခြင်း၊ sandboxing နဲ့ ပြန်ပြင်မရနိုင်တဲ့ လုပ်ဆောင်ချက်တွေအတွက် လူကိုယ်တိုင် အတည်ပြုချက် (human approval) ရယူတာမျိုးတွေကို ထည့်သွင်းပါ။
- CI ထဲမှာ SAST (Semgrep/CodeQL)၊ dependency/SCA (OSV-Scanner) နဲ့ secret scans (gitleaks) တွေကို run ပါ။
- စိတ်မချရတဲ့ fixture ဖိုင်တစ်ခုထဲမှာ အန္တရာယ်မရှိတဲ့ indirect prompt injection စာသားတစ်ခုကို သက်သက် ထည့်သွင်းထားပါ။ Agent က အဲဒီစာသားကို ညွှန်ကြားချက်အဖြစ် မယူဘဲ data သက်သက်အဖြစ် မှန်မှန်ကန်ကန် သဘောထားကြောင်း စစ်ဆေးပြပါ။
- Credential ပေါက်ကြားမှု၊ မသမာတဲ့ tool output ထွက်ပေါ်မှုနဲ့ ငွေကုန်ကြမ်းသွားတဲ့ အခြေအနေတွေအတွက် ကိုင်တွယ်ဖြေရှင်းမယ့် incident playbook အတိုတစ်ခု ရေးဆွဲပါ။