# AI security workshop materials

Kevin O'Connor, TKOResearch. Version 1.0, September 9, 2026.

Use these materials for a three-hour agent security workshop or a separate 90-minute detection evaluation session. Participants work with local, synthetic examples to practice access reviews, control checks and deployment decisions. The exercises do not test TARE or any production application.

## Choose and prepare a session

- [Facilitator guide and run sheet](facilitator-guide.md): preparation, timed instructor steps, failure discussions and debrief.
- [Participant packet](participant-packet.md): scenario, prerequisites and individual/pair tasks.
- [Worksheets and rubric](worksheets.md): copyable scope, authority, test, decision and evaluation sheets.
- [Agent solution notes](agent-solutions.md): expected checks, code locations and teaching limits.
- [Detection module](detection-module.md): rule, case labels, baseline and assisted workflow.
- [Detection solution notes](detection-solutions.md): counting rules, expected results and analyst reasoning.
- [Detection labels and simulated suggestions](detection-fixture.json): machine-readable case-level fixture. Reveal the suggestions only after recording the baseline.
- [Detection scoring script](evaluate_detection.py): local reproduction of the published counts against the original identity script.

Download the Markdown files and open them in a text editor or Markdown viewer. Relative links work when these materials are kept in the same directory. Use the website links below to obtain the existing executable examples; no package installation or AI subscription is required.

## Core workshop setup

Python 3.10 or later and its standard library are sufficient. Download and inspect these original files into one local working directory:

- [Document permissions](https://www.tkoresearch.com/examples/agent-security-review/document_permissions.py)
- [Retrieval boundaries](https://www.tkoresearch.com/examples/agent-security-review/rag_boundaries.py)
- [Credential lifecycle](https://www.tkoresearch.com/examples/agent-security-review/credential_lifecycle.py)
- [Original reference README](https://www.tkoresearch.com/examples/agent-security-review/README.md)

```sh
python3 document_permissions.py
python3 rag_boundaries.py
python3 credential_lifecycle.py
```

The September 9 reference checks pass 14, 8 and 8 test methods respectively. The tests run against in-memory fixtures. Participants may pair with someone running Python or read the assertions and solutions. Inspecting a test is a source review; record that separately from executing it.

## Detection setup

Download [KevinBytes identity_hunt.py](https://www.kevinbytes.com/examples/security-writing/identity_hunt.py) and [its recorded results](https://www.kevinbytes.com/examples/security-writing/identity-hunt-results.json). Put `identity_hunt.py`, `evaluate_detection.py` and `detection-fixture.json` in the same directory. Inspect the Python files before running:

```sh
python3 identity_hunt.py
python3 evaluate_detection.py
```

The scorer runs the local identity script and checks its results against the worksheet labels. It does not fetch files, contact a model, read credentials or change a cloud service. An optional first argument supplies the path to the downloaded identity script. Its output remains in the terminal unless you deliberately save it.

## Working boundaries

Use invented data and local fixtures. Keep credentials, client materials and sensitive system diagrams out of these public examples and public contact forms. For a session tailored to your team, start with a redacted workflow summary and agree on the systems and decisions to cover. The exercises do not require changing a live system.

The supplied scripts do not need persistent databases. The scorer suppresses bytecode generation; if you import examples yourself, Python may create `__pycache__`. Downloaded files and any outputs you save are yours to retain or remove. No provider cleanup is required.

For context, read the [preparation article](https://www.tkoresearch.com/blog/preparing-for-an-ai-agent-security-workshop) and [NIST AI RMF 1.0](https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf), January 2023. NIST has not endorsed or certified this workshop.
