The dangerous instruction arrived as data.
You own the Agent's trust and capability boundary.
A support Agent reads external knowledge while answering refund questions. One retrieved page includes instructions asking it to enrich the answer with full CRM data and send account identifiers through an allowed tool path. A second attack is subtler. A benign security article also contains attack-like wording.
Block malicious instruction flow and sensitive tool reach while keeping useful external knowledge available and avoiding excessive false positives or human review.
A prompt can be untrusted data even when it looks like an instruction.