This mirrors foundation-introduction-to-deepagents, the course the LCAE exam guide labels Deep Agents Foundations. It is one of two courses the guide names for the Build section, and the guide's weighting indicates deepagents is roughly half of it. Everything is here: the constructor and its six additions, the fixed middleware stack, models, the system prompt after v0.7 emptied its base, tools and MCP, threads and checkpointers, human-in-the-loop gates, the execution environment where sandboxes are backends and the default shell policy is full host access, the context numbers that make the best quiz questions, skills against always-loaded memory, delegation as a context lever, and a full project derivation at the end. Every default in this library resolves toward capability, and that is the through-line.
You have every part. The exam asks whether you can put them together and defend the parts you left alone.
Pick a system you genuinely own and would genuinely automate. Not a toy. Something where you would feel the consequences of getting it wrong, which means you will make honest decisions rather than tidy ones.
Then produce two documents in a scratch file. No cloud account, no deployment, no provisioned anything.
create_agent or create_deep_agent, and one sentence naming what you would have to hand-assemble if you picked the lower one. If your answer is “nothing, it is only defaults”, you have understood module 1.execute is granted at all, and which shell policy if any. State explicitly what your sandbox does not protect you against.interrupt_on, with the reversibility judgement that put each one there, and at least one irreversible tool you deliberately left ungated along with the reason.SKILL.md, with the reason expressed as a token-cost argument rather than a taste argument.This is the half that makes the exercise worth doing.
Write the post-mortem of the failure your design would actually have. Not a hypothetical, the likely one. Give it a date, a trigger, a blast radius and a detection story.
Three questions it must answer:
Every number in document one is either a documented default you can name, or a deliberate override with a reason attached. No number appears because it sounded about right.
And document two names a real failure mode rather than a polite one. “The agent might occasionally be less accurate” is not an incident report. “The shell policy defaulted to the host, an injected page told it to read the deploy key, and nothing logged it because reads are not gated” is.
That is the discipline the whole course is aimed at. The exam tests whether you know which layer owns which concern and what happens when a default is left alone. The capstone asks the same question once, about a system you would have to live with.