The term prompt injection gives the impression of some control for the user. The term used in the below video "text-in is text-believed" makes the problem of AI agents clearer. As the video explains, any text source is used, including incoming mail. To me this sounds like the unacceptable mix-up of data and code, which in normal software we fiercely avoid, and which hackers normally need things like a buffer overflow to achieve. But AI agents don't just have a buffer overflow vulnerability, they are the buffer overflow vulnerability.