Indirect Prompt Injection at the Tool-Response Boundary: What the AI Gateway Actually Sees
A defender-oriented look at detecting indirect prompt injection in MCP-mediated and tool-calling agent stacks: which gateway fields matter, what the first week of alerting looks like, and where most detection programs miss the actual trust boundary.