Indirect prompt injection in tool-calling agents: detection shape and the first week of tuning
A defender’s view of indirect prompt injection in MCP-connected and tool-calling LLM agents — what the telemetry actually looks like, where detections originate noise, and how to map containment to 800-53.