Prompt injection is easy to underestimate when the model can only answer with text. The worst outcome looks like a bad summary, a leaked instruction, or a response that followed the wrong source.
In a tool-using agent, that assumption breaks fast.
A โฆ