The HN discussion splits between “overblown” and “inevitable.” I’d ask a narrower question: if your production agents ingested a malicious instruction inside a retrieved document tomorrow, what actually stops it at the tool-call boundary?