# Mithril Dojo — AI Agent White-Hat Training

## Promise and audience

A practical program for security, engineering, AI product, and governance teams. Learners practise planning, constraining, supervising, and documenting AI-assisted security review inside an explicitly authorized, isolated exercise. It teaches safe decisions and evidence quality; it does not replace professional testing or promise that attendance makes a product secure.

Foundation has no offensive-security prerequisite. Practitioner learners should understand basic HTTP and software development. All exercises use supplied fictional text and synthetic data. No public scanning, credential collection, persistence, stealth, or destructive activity is part of the course.

## Learning path

| Module | Outcome | Practice |
| --- | --- | --- |
| 0. Authorization and scope | Identify authority, target, methods, exclusions, time window, data rules, stop conditions, and reporting channel | Decide whether an intentionally incomplete fictional request is ready |
| 1. AI agents in security work | Explain tools, delegation, memory, uncertainty, and human accountability | Map a fictional review workflow |
| 2. Safe agent setup | Apply least privilege, read-only defaults, egress limits, short-lived access, and human approval | Complete a policy worksheet; no executable agent is supplied |
| 3. Threat modelling | Identify untrusted inputs, prompt injection, tool overreach, data exposure, and confused-deputy risks | Review a fictional workflow diagram |
| 4. Evidence before conclusions | Separate observation, hypothesis, reproduction, impact, and uncertainty | Build a ledger from synthetic logs |
| 5. Proof quality | Prepare minimal, safe, reproducible evidence another reviewer can validate | Review an incomplete fictional Proof packet; do not execute payloads |
| 6. Remediation and retest | Define mitigation, owner, acceptance condition, and safe retest | Match a fictional finding to a defensive control |
| 7. Responsible disclosure | Use the authorized channel and protect sensitive information | Draft a fictional private report |
| 8. Capstone | Deliver a scope sheet, agent policy, evidence ledger, report, and retest plan | Team tabletop using the paper-based synthetic lab pack |

## Delivery and assessment

Foundation is a two-hour facilitated briefing with three short video lessons. Practitioner is a one-day supervised tabletop. Cohort delivery spans four weekly sessions. Assessment weights are 25% each for authorization/scope, agent safety, evidence/Proof, and remediation/communication. Passing requires at least 15/25 in each domain and no safety-gate failure. Proceeding without authorization or proposing an out-of-scope action fails the safety gate regardless of total score.

Completion records show course version, date, modules completed, and rubric result. They are training records, not independent professional certification or assurance attestations.

Optional credential orientation maps selected Dojo outcomes to public CISSP® and CISA® domains. It does not cover either exam end to end, predict results, or grant credentials. See `credential-pathways.en.md`; use the original mini-check as a diagnostic only.

## Enterprise delivery

Agree audience, objectives, language and accessibility, lab delivery, data handling and retention, facilitator responsibilities, and escalation contacts before delivery. Synthetic data is the default. The current lab pack is paper-based; it does not include a live vulnerable service. Do not submit client source, credentials, reports, or production data to third-party AI services as part of training.

## Evaluation

Compare baseline and end-of-course scenario scores, safe-scope decisions, evidence completeness, and learner confidence. Report aggregate outcomes by default. Do not claim reduced incidents or improved security posture without separate longitudinal evidence.
