How prompt injection attacks LLM apps and agents: direct and indirect injection, data exfiltration, the lethal trifecta, and defenses that actually hold.