AI Engineering from Scratch: choose a route through the curriculum
Security and maintenance for a learner’s AI workbench
Protect credentials and keep optional agent instructions in a scope you can inspect.
What you will learn
- Separate examples from accounts
- Review the tutor’s authority
- Maintain a reproducible workspace
Before you start
- Basic command-line access
- A bounded learning goal and disposable checkout
Turn lesson commands and code changes into a reviewable record of what you can do.
Key takeaways
- Learning logs can expose credentials.
- Agent skills need a deliberate scope.
- Pinning source makes later changes reviewable.
Separate examples from accounts
The course includes lessons on API keys, data handling, Docker and agent tooling. Use disposable credentials and synthetic inputs during practice. A transcript that contains a provider token can turn a useful lab receipt into a leak.
Read scripts before executing them, especially when they install packages or alter an agent host. Pin the repository revision and note any network downloads; a course checkout is still executable third-party code.
Review the tutor’s authority
The optional skill installer asks for a host and project or global scope. A project-local install is easier to inspect and remove during a trial. Confirm the installed files and host-specific invocation before allowing the tutor to modify another repository.
Course instructions, generated answers and external examples are data for learning. They should not automatically gain authority over local files, cloud credentials or deployment steps. Keep approval boundaries outside the lesson text.
Maintain a reproducible workspace
Use a clean branch or disposable directory for experiments. Record dependency versions and keep notebooks, outputs and generated files separate from source lessons so updates do not erase your work.
If a lesson changes upstream, compare the pinned version with the new file before repeating an old command. This review did not audit every dependency or certify the repository for sensitive environments.
Decision guide
| Criterion | Option A | Option B |
|---|---|---|
| Best when | You need predictable behavior and easy auditing | You need adaptive optimization and have reliable telemetry |
| Main risk | May leave performance on the table | Can become difficult to explain or debug |
Implementation steps
- 1
Create a disposable project-local study environment.
- 2
Inspect optional installer destinations and permissions.
- 3
Scan saved outputs for secrets before sharing them.
Copy-ready example
study_workspace:
repository_revision: bf7791e140768d8223d24e616bb60cbf07fea014
agent_skill_scope: project
inputs: synthetic
shared_logs: redact-secretsFrequently asked questions
Should the tutor use global scope?
Start with project scope unless you explicitly want its instructions available across projects.
Can I use customer data in the exercises?
Start with synthetic data and review each lesson’s data path before introducing real records.
Sources
- AI Engineering from Scratch / README.mdSource checked 2026-09-29
- AI Engineering from Scratch / docs/i18n.mdSource checked 2026-09-29