Connecting an AI agent to internal tools is the first time most teams confront a security boundary that is not enforced by code alone. Traditional programs take instructions from developers and data from users; an LLM-driven agent takes instructions from both , and it cannot reliably tell them apart. A field value, an issue comment, a web page, or a tool description can all contain text that changes what the model does next. The Model Context Protocol does not solve this; it makes the boundary ...