The Internet's New Scarcity: Skill 2 — Digital Identity Exposure Check
Inventory where you've proved you're human — exposure ledger, irreversible exposures, consent audit, one revocation to attempt
Chapter XIV
Cards marked with a teaser are in the Vault. Unlock everything — $97, one time.
Inventory where you've proved you're human — exposure ledger, irreversible exposures, consent audit, one revocation to attempt
Pre-launch reviewer that will tell you when not to launch
Security-minded second reader that assumes nothing is safe until checked
which open-weight models you can run
Prompt 2: The Hardware Reality Check You might already own hardware capable of running local AI models. This prompt tells you exactly what is possible on your machine. I want to find out if I can run AI models locally on my current hardware. My specs: - Computer: [MAKE AND MODEL, e.g., MacBook Pro M3 Max, Dell XPS 15, custom desktop] - RAM: [AMOUNT, e.g., 32GB, 64GB] - GPU: [MODEL AND VRAM, e.g., NVIDIA RTX 4070 with 12GB VRAM, Apple M3 Max with 40-core GPU, or "integrated graphics only"] - Storage: [AVAILABLE SPACE, e.g., 500GB free on SSD] - Operating system: [macOS, Windows, Linux] Based on these specs: 1. List which open-weight models I can run comfortably (with expected tokens per second) 2. List which models I could run but would be slow 3. Recommend the single best model for general professional use on my hardware 4. Tell me the one hardware upgrade that would give me the biggest improvement 5. Compare my local capability to Vitalik Buterin's setup (NVIDIA 5090 laptop at 90 tokens per second) so I have a realistic benchmark Be specific with model sizes (7B, 14B, 35B, etc.) and quantization levels (Q4, Q5, Q8).
plan migration to local AI
stand up a local model fast
map what crosses the trust boundary
classify data sensitivity + regulatory flags
set AI tool permissions deliberately
build a PII pre-scanner script
build a PII-flagging Chrome extension
build a data firewall for the agent
check content before AI processes it
Prompt 2: Document safety scanner - check content before AI processes it THE PURPOSE : Before asking AI to summarize, analyze, or process any document from an external source, you should know what’s actually in it. This prompt creates a systematic check for hidden content that could contain prompt injection attempts. It’s not foolproof since sophisticated attacks use encoding and obfuscation, but it catches obvious attempts and builds the habit of verifying before processing. Copy and customize this prompt: I’m about to ask an AI assistant to process a document from an external source. Before I do, I need to check it for potential prompt injection attempts. Document details: - Source: [Who sent it / where I got it] - File type: [PDF, Word, email, etc.] - Stated purpose: [What it claims to be] - Trust level of source: [Known/Unknown, Trusted/Untrusted] Help me create a pre-processing safety check: 1. CONTENT EXTRACTION If I can copy text from the document, what should I look for: - Instructions directed at AI systems (”ignore previous,” “system prompt,” “execute”) - Text that references the AI reading the document - Unusual formatting indicators (font size changes, color specifications) - Markdown or code-like syntax in unexpected places - URLs or image references with query parameters 2. METADATA CHECK For this file type, where could hidden content be stored: - Document properties/metadata fields - Comments or tracked changes - Speaker notes (if presentation) - Hidden text or white-on-white text - Image alt text or descriptions 3. RED FLAGS CHECKLIST Check these specific patterns: [ ] Contains phrases like “ignore,” “disregard,” “forget” followed by “instructions” [ ] References “system prompt,” “context,” or “previous conversation” [ ] Includes URLs with unusually long query strings [ ] Has unusual invisible characters or zero-width spaces [ ] Contains instructions about what to say, output, or respond 4. SAFE PROCESSING RECOMMENDATION Based on trust level [TRUSTED/UNTRUSTED] and file type [TYPE]: - Process normally / Process with caution / Don’t process with AI - If processing, what content to exclude - Alternative approaches (manual review, sanitized copy) 5. SANITIZATION STEPS If I decide to process it, how to reduce risk: - Copy only specific sections rather than whole document - Remove all formatting (paste as plain text) - Manually review before AI processing - Use AI without plugins or integrations enabled
what to do if something goes wrong
audit what your AI tools can access
summarize external content with guardrails
map your prompt-injection exposure
assess exposure + rotation plan
Prompt 2: Credential exposure audit - assess damage and create response plan THE PURPOSE : If you have already used AI browsers with authenticated systems, you may have exposed credentials to prompt injection attacks without knowing it. According to 2025 Incident Response Data , organizations often discover compromised credentials months after initial exposure, with median dwell times of 90 minutes before attackers begin data exfiltration. This prompt helps you identify which accounts may be compromised, assess the risk level of each exposure, and create a prioritized credential rotation plan. Use this if you have used AI browsers while logged into sensitive systems. Copy and customize this prompt: I have been using [AI BROWSER NAME] while logged into various systems. I need to assess potential credential exposure and create a response plan. EXPOSURE INVENTORY In the past [TIMEFRAME: 30/60/90 days], I have used AI browsers while logged into: - Banking/financial: [INSTITUTIONS SIMILAR TO YOURS] - Email accounts: [LIST PROVIDERS SIMILAR TO YOURS] - Corporate systems: [LIST: VPN, CRM, project management, etc. (SIMILAR, NOT THE SAME AS, YOURS)] - Cloud storage: [LIST: Google Drive, Dropbox, etc.(SIMILAR TO YOURS)] - Social media: [LIST PLATFORMS (SIMILAR TO YOURS)] - Other authenticated systems: [LIST (SIMILAR TO YOURS)] For each system, specify: - Frequency of use while AI browser was active - Sensitivity level of data accessible (Critical/High/Medium/Low) - Whether multi-factor authentication (MFA) is enabled - Whether you saved passwords in browser or used auto-fill RISK ASSESSMENT For each listed system, evaluate: 1. Exposure severity (Critical: financial/corporate / High: email/cloud / Medium: social/shopping / Low: non-sensitive) 2. MFA protection status (None/SMS/App-based/Hardware key) 3. Potential impact of compromise (financial loss, data breach, reputational damage) 4. Indicators of compromise to monitor (unauthorized logins, unusual activity, data exfiltration) PRIORITIZED RESPONSE PLAN Create a credential rotation schedule: IMMEDIATE (Within 24 hours): - Critical systems without MFA - Financial accounts - Corporate VPN and admin access URGENT (Within 72 hours): - Email accounts (as they enable password resets elsewhere) - Cloud storage with sensitive data - Critical systems with MFA STANDARD (Within 7 days): - Remaining authenticated systems - Social media accounts - Shopping and subscription services For each priority tier, provide: - Specific accounts to rotate - Steps: Change password, enable MFA if missing, review recent activity logs, revoke active sessions - Monitoring actions: Set up login alerts, review connected apps, check for unauthorized changes COMPROMISE DETECTION CHECKLIST What to look for in each system: - Unauthorized login locations or devices - Password reset attempts you did not initiate - Changes to security settings or recovery information - Unusual account activity or data access patterns - New connected applications or API access grants OUTPUT FORMAT - Risk-ranked list of potentially exposed accounts - Day-by-day credential rotation schedule - Specific steps for each account (password change, MFA setup, session revocation) - Monitoring checklist to detect unauthorized access - Long-term recommendations (password manager, hardware security keys)
org guidelines for AI browser use
test config for prompt-injection vulnerabilities
risk-based protection for shared GPTs
keep the AI knowledge base current (inventory, audits)
contact hierarchy + meeting points + out-of-area coordinator
Prompt 1: Complete Family Emergency Architecture <role>Emergency Management System Architect specialized in family preparedness</role> <context> You're designing a communication system assuming: - 90% voice network failure - Internet intermittent or unavailable - Power outages likely - Family members separated across 5+ miles - School/workplace lockdown protocols active </context> <task> Guide me through creating a complete family emergency communication architecture. I will use these inputs: <family_data> Members: [List names, ages, typical locations] Addresses: [Home, work, school for each] Contact methods: [Phone numbers, emails for each] Medical needs: [Medications, conditions, allergies] Pets: [Types, special needs] </family_data> <requirements> 1. Design three-tier contact hierarchy (primary/secondary/tertiary) 2. Establish two physical meeting points with GPS coordinates 3. Designate out-of-area coordinator with specific duties 4. Create time-window check-in protocol 5. Include special provisions for vulnerable members 6. Reference Ready.gov and FCC guidelines explicitly </requirements> <output_format> Section 1: Contact Architecture Table - Member | Primary | Secondary | Tertiary | Special Notes Section 2: Meeting Points - Location | Address | GPS | Identifying Features | Backup if Unavailable Section 3: Check-in Protocol - Time windows, message templates, escalation triggers Section 4: Quick Reference Card (wallet-sized) </output_format> <constraints> - Every protocol must work with SMS only - No assumption of internet availability - Maximum 160 characters per message - Include failure contingencies </constraints> </task> Customization notes: Replace family_data section with your actual information. Add specific medical or mobility constraints. Expected output: Complete communication plan with printable reference cards and specific protocols.
sync school/work/legal during a crisis
run a family emergency drill with a rubric
channel redundancy + store-and-forward relay
wallet/fridge/glovebox cards + QR backup
before/during/after disaster protocol with evac item tiers
cardiac/health crisis response plan (solo vs with help)
income-loss survival protocol (triage→recovery)
find weaknesses/cascade failures in an emergency plan
80/20 high-impact prep in limited time
phased-interview → stress-tested household emergency protocol
prioritized lockdown: vulnerabilities→settings→isolation→recovery→maintenance
password system: manager setup, MFA strategy, emergency access
exposure assessment + data removal request templates
legacy access + asset preservation + service termination
effort-vs-protection tradeoffs + implementation time estimates
account closure priority + automated cleanup tools
password generation/storage, audit, emergency access
executor guide + per-account instructions + secure sharing
legacy-aware zero-trust vault, RFC-2119 output + mermaid diagrams
offline bank-CSV analysis prompt for Jan.ai / local LLM
deflection + file-security boundaries vs prompt injection
red-team your own GPT for instruction/config leakage
instruction line that blocks setup/file/instruction disclosure