Mithril Dojo is a learning and practice program for white-hat researchers working with AI agents. Learn to define authorization, constrain agent capabilities, supervise decisions, and produce verifiable evidence and remediation plans.
AI Agent White-Hat Learning Path
Learn from fundamentals to a team capstone using synthetic data and a paper-based tabletop. No testing of real third-party systems is included.
0 · Authorization and scope Confirm target, methods, time window, exclusions, and stop conditions
1 · How AI agents work Understand models, tools, memory, delegation, and human accountability
2 · Safe agent setup Least privilege, read-only defaults, network limits, and approval gates
3 · Threat modelling Recognize untrusted input, excessive authority, and data exposure
4 · Evidence to conclusions Separate observations, hypotheses, reproduction, impact, and uncertainty
6 · Remediation and retest Define mitigation, owner, acceptance condition, and retest
7 · Responsible disclosure Protect sensitive data and use the authorized channel
8 · Team capstone Create scope, agent policy, evidence ledger, and report from a synthetic case
Assessment covers authorization and scope, safe agent control, evidence quality, and remediation/collaboration. A safety-gate failure cannot be offset by points elsewhere.
Video lessons
Start with the English cyber-defense walkthrough below. The three foundation videos have Japanese synthetic narration and selectable English captions.
Cyber Defense with Mithril App and Desktop
An English illustrated exercise for whitehats and engineers: scope, synthetic log review, local work, remediation, and retest. English synthetic narration and captions; no live incident or automatic-defense demonstration.
A shared, practical method for security, engineering, and AI governance teams to supervise AI agents safely. Pricing is scoped to cohort size, language, and delivery requirements.
Foundation · 2 hours
Briefing, scope clinic, three short videos, and team checklist.
Practitioner · 1 day
Facilitated synthetic tabletop, agent policy, evidence review, and capstone.
Cohort · 4 weeks
Weekly workshops, guided practice, office hours, and portfolio review.
Enterprise · scoped
Tailored audience, language, accessibility, and approved scenarios.
Includes facilitator guide, learner workbook, paper-based synthetic lab pack, assessment rubric, and completion record. Completion is not professional certification or compliance attestation. English page and written materials are available. The cyber-defense walkthrough has English narration and captions; the three foundation videos have Japanese narration with selectable English captions.
CISSP® / CISA® domain mapping and original mini-checks are learning orientation only, not exam preparation, official items, or credentials. Dojo does not award or guarantee CPE hours. No individual instructor credential is currently listed as verified.
Synthetic targets only. No production testing, exploit deployment, persistence, stealth, credential theft, or destructive activity. No live vulnerable service is included in the current lab pack.
Ranking data is not connected. No individual positions or scores are shown until verified contribution data is available.
Axes: overall · verified reports · remediation contribution · Proof quality. Only public work explicitly approved by its author may appear.
Contribution points (1,000)
Verified reports Novel findings with validated reproducibility400 pts
Remediation Contribution to fixes and mitigation250 pts
Proof quality Reproducibility, completeness, and safety200 pts
Ethics and collaboration Scope, responsible disclosure, and teamwork100 pts
Sustained contribution Consistent work over up to 12 months50 pts
Token spend or usage is optional profile information. It never earns points or affects promotion.
Promotion rules
Points are guidance. Each promotion also requires review of report validity, scope compliance, safe Proof, and conduct. Duplicate and invalid reports earn no points.
Verified identity is required to apply for shodan and above. Identity verification is private and adds no points.
Kyu and dan guide
Cumulative points and titles. Dan ranks require review.
Rank
Points
Title
White belt
0–99
Learner
10th kyu
100
Explorer
9th kyu
150
Explorer
8th kyu
200
Explorer
7th kyu
250
Investigator
6th kyu
300
Investigator
5th kyu
350
Investigator
4th kyu
400
Researcher
3rd kyu
450
Researcher
2nd kyu
500
Researcher
1st kyu
550
Researcher
Shodan
600
Verified researcher
Nidan
640
Experienced researcher
Sandan
680
Experienced researcher
Yondan
720
Senior researcher
Godan
760
Senior researcher
Rokudan
800
Senior researcher
Nanadan
840
Mentor
Hachidan
880
Mentor
Kudan
920
Mentor
Judan
960
Honorary mentor · individual review
Shodan (black belt) requires practical foundations in both technical and business competencies. Nidan and above require advanced practice integrating both axes.
Aliases are allowed. Identity documents and verification details are never public. Profile and award information appears only when the researcher chooses to publish it.
Confirm authorization before research and follow responsible disclosure procedures. This ranking does not authorize or encourage exploitation or testing outside scope.