Map and defend the agent-era attack surface — RAG poisoning, document-borne payloads, memory poisoning, and tool-output hijacking that direct-injection defenses don't reach.