Assume the injection works.
Your agents read email, tickets and documents you don’t control. A sentence in them becomes an instruction.
The rule decides, not the model. A model fooled 2% of the time and one fooled every time meet the same rule.
Anyone who can put text in front of an agent can act with its credentials: an email, a ticket, a PDF, a web page. Tool descriptions are the fastest-growing channel. OWASP LLM01:2025: no fool-proof prevention of prompt injection is known. UK NCSC, 2025-12-10: it may never close the way SQL injection did.