# Mithril Dojo — AI Agent White Hat Training

## Product promise

A practical, instructor-led and self-paced program for security, engineering, and AI governance teams. Learners practise how to plan, constrain, supervise, and document AI-assisted security review using supplied fictional text in a paper-based tabletop. The program teaches safe decision-making and evidence quality; it does not promise that a course or badge makes a product secure or replaces professional testing.

## Audience and prerequisites

- Security analysts, application engineers, AI product teams, and security managers.
- No offensive security experience required for Foundation. Learners should understand basic HTTP and software development for the Practitioner lab.
- The current exercises use supplied fictional cards and logs in a paper-based tabletop; no executable target or agent is supplied. No public target scanning, credential collection, persistence, stealth, or destructive activity is part of the course.

## Learning path

| Module | Lesson | Learner outcome | Practice |
| --- | --- | --- | --- |
| 0 | White-hat charter and scope | Distinguish written authorization, scope, exclusions, time window, and stop conditions | Mark an intentionally ambiguous fictional authorization as ready or not ready |
| 1 | How AI agents change security work | Explain tool use, delegated actions, memory, uncertainty, and human responsibility | Draw the data and action flow for a fictional review agent |
| 2 | Safe agent setup | Apply least privilege, read-only defaults, egress restrictions, short-lived credentials, and human approval gates | Write a policy checklist for the fictional assistant; no real credential is used |
| 3 | Threat modelling AI-assisted workflows | Identify prompt injection, untrusted input, tool overreach, data exposure, and confused-deputy risks | Review a fictional agent workflow diagram and record risks without testing a live system |
| 4 | Evidence before conclusions | Separate observation, hypothesis, reproduction, impact, and uncertainty | Turn a synthetic log excerpt into an evidence ledger with source and confidence |
| 5 | Proof quality and reproducibility | Produce a minimal, safe reproduction that another reviewer can validate | Improve a deliberately incomplete fictional Proof packet; do not execute payloads |
| 6 | Remediation and retest | Write a bounded mitigation, owner, acceptance criteria, and safe retest plan | Match synthetic findings to defensive controls and retest evidence |
| 7 | Responsible disclosure and collaboration | Communicate through the authorized channel, protect sensitive data, and coordinate timelines | Draft a fictional private report and a concise remediation handoff |
| 8 | Capstone: supervised review | Deliver a scope sheet, agent policy, evidence ledger, prioritized report, and retest plan | Team tabletop using the supplied fictional case and text; instructor scores rubric |

## Delivery and assessment

- Foundation: 2-hour facilitated briefing plus three short video lessons.
- Practitioner: one-day workshop, supervised lab, and team capstone.
- Cohort: four weekly sessions with office hours and a final evidence portfolio.
- Assessment rubric: scope/authorization 25%, safe agent constraints 25%, evidence and Proof 25%, remediation and communication 25%. Pass requires every safety-critical item; a high aggregate score cannot compensate for an out-of-scope action.
- Learners receive a completion record with course version, date, modules completed, and rubric result. It is a training record, not an independent professional certification or assurance attestation.
- Optional credential orientation maps selected Dojo outcomes to public CISSP® and CISA® domains. It does not cover either exam end to end, predict results, or grant credentials. See `credential-pathways.md`; use original mini-questions as diagnostics only.

## Enterprise implementation

Before delivery, agree audience, learning objectives, accessibility and language needs, tabletop delivery model, data handling, retention, instructor responsibilities, and escalation contacts. Use synthetic data by default. Do not upload client source code, credentials, vulnerability reports, or production data into third-party AI services as part of training. Any customer-specific scenario must be approved and sanitized in advance.

## Evaluation

Measure baseline and end-of-course scenario scores, safe-scope decision accuracy, completeness of evidence packets, and learner confidence. Report cohort-level aggregates only unless the customer explicitly agrees to named learner reporting. Do not claim reduced incidents or improved security posture without separate longitudinal evidence.
