The piece everyone handing an agent tools should read. Willison’s "lethal trifecta": access to private data + exposure to untrusted content + the ability to communicate externally — together, one poisoned input is enough for an agent to exfiltrate data, with no classic software flaw involved. The core: an LLM cannot reliably separate an operator’s instruction from an injected one, and guardrails alone do not fix it. Which is exactly why the Hugging Face incident was structural, not a one-off.