Defend against prompt injection in agent tools using context separation and data tainting. Prevent tool outputs from hijacking agent reasoning.