Probabilistic systems don’t have zeros.
Your agents read email, tickets and documents you don’t control. Whoever writes to those writes to the agent.
Assume the injection works. A model fooled 2% of the time and one fooled every time meet the same grant.
Anyone who can put text in front of an agent can act with its credentials: an email, a ticket, a PDF, a web page. Tool descriptions are the fastest-growing channel. OWASP LLM01:2025: no fool-proof prevention of prompt injection is known. UK NCSC, 2025-12-10: it may never close the way SQL injection did.