Provides a layered prompt-injection defense procedure for agents that consume untrusted content — web pages, tool output, repository files, agent-authored notes. Covers ingress enumeration, normalizing before classifying, warn-versus-block policy, canary tripwires, fail-open ordering, and adversarial validation. Use when designing or reviewing an agent's trust boundaries.