Tool-Call Divergence: Detecting Indirect Prompt Injection in Agentic Systems
A defender-oriented analysis of indirect prompt injection in tool-calling agents: where the signal actually lives in the trace pipeline, what the first week of tuning has to fix, and which 800-53 controls the implementation maps to.