Skip to main content
Theory is cheap. This lab makes you attack one real workflow you already use, find the leakage paths, and rewrite the workflow so those paths are closed. Plan for about 25 minutes. You need a workflow from your actual job — not a toy example — and access to the Claude surface where it usually runs.
Part 1

Pick a workflow and map what enters it

7 min
Part 2

Red-team five leakage paths

10 min
Part 3

Rewrite the safer version and prove it

8 min

Part 1: Pick and map

Choose a workflow you have run, or nearly run, with Claude in the last month. Good candidates:
  • Drafting a customer email from CRM notes
  • Summarizing a meeting with an attached transcript
  • Researching competitors with web search plus internal docs
  • Building a slide outline from a board pack
  • Asking Cowork to tidy files or prepare a report
Write the map on paper or in a scratch note. Four lines only:
  1. Trigger — what starts the job
  2. Inputs — exact files, pastes, connectors, or tabs Claude sees
  3. Actions — what Claude may do (draft, search, send, edit, schedule)
  4. Outputs — where the result goes (chat, artifact, email, ticket, shared project)
If you cannot name the inputs precisely, that is already a finding. Vague inputs are how secrets travel.

Part 2: Red-team the paths

Attack your own map. For each path below, write either closed, open, or unknown, and one sentence of evidence.
Path A · Unauthorized input

Is any input something you are not clearly allowed to give an outside system? Look for customer PII, credentials, NDA’d files, unreleased numbers.

Path B · Over-broad context

Does the project, paste, or connector give Claude a whole archive when the task needed three paragraphs?

Path C · Quiet egress

Could web search, thumbs-up feedback, Chrome screenshots, or a connector result carry sensitive detail out of the room without a share click?

Path D · Loud share

If someone shared the chat, artifact, or project tomorrow, who newly sees the inputs? Use the radius language from Sharing.

Path E · Action risk

If Claude can send, edit, delete, or schedule, is there an approval gate — or could a vague verb and a tired Allow click finish the leak for you?

Score yourself honestly. Three or more open / unknown paths means the workflow is not ready for unsupervised use. While you are here, reread the injection lesson in Failure modes if the workflow reads untrusted email, tickets, or web pages and can also take actions. That combination is its own attack path.

Part 3: Rewrite and prove

Rebuild the workflow until every open path is closed or explicitly accepted by policy. Use this rewrite pattern: Then run the safer version once on harmless or redacted data. You are proving the new path works, not re-proving the risky one.

Flight card

Check items off as you land them. All ten is a completed lab.

Debrief with your facilitator

  1. Which leakage path was open that you had not noticed before this lab?
  2. What did you remove from the inputs, and did the task still work?
  3. If this workflow used a connector or Cowork, which tool stays on Needs approval permanently?
  4. What is the one sentence you will use as your personal stop rule before pasting?

Carry forward

Pin one rule above your desk or in your project instructions:
Permission before paste. Radius before send. I own the outcome.
That is the whole section, compressed to a habit.