Why prompt injection exists, how attackers exploit it, and the layered defense every LLM-powered feature needs before shipping.