Prompt injection is less about breaking a model and more about tricking a system into treating hostile text as trusted instruction - a growing problem for AI tools that browse, retrieve, and act.