A UI architect who tries to own security gets it wrong. One who can’t recognise a problem ships a liability into ninety portfolio-company products and finds out about it from someone else’s incident review. The skill in between is narrow and learnable: see the thing, ask the right question, know whose answer it is, and know what a real answer sounds like so the question can actually close.
Start lesson one: Model output is untrusted input →
That agent output lands in a component you wrote. That the component renders it as something richer than a plain string. That somewhere in the product a human reviews model output against source data before something downstream fires — a review gate, a trace view, an approval screen. If that describes what you build, the rendered surface is part of the attack surface, and nobody else on the team is looking at it.
This course is being written as you work through it. The first module is ready; the remaining two are registered so the lesson numbering never shifts under you. Ask your teaching agent for the next module once the flag log has real rows in it.
Everything an agent hands your component is attacker-influenced content, and the component is where a backend problem becomes a user problem.
Review surfaces and trace views exist to show everything, which is exactly the problem when everything includes personal data.
A flag that gets dismissed, or that blocks every release, is worth about the same as no flag at all.
Every claim on these pages links to its source. If a source looks wrong or out of date, check the resource list and tell your teaching agent — the course is meant to be corrected.