Autonomous agents don't just answer questions anymore — they browse the web, read emails, call APIs, and take actions on your behalf. That autonomy is exactly what makes prompt injection one of the most serious open problems in AI security today. Any untrusted content an agent reads — a webpage,