Review or design security boundaries for LLM agents and tool-calling systems. Use whenever a model can choose actions, call tools, invoke MCP-style capabilities, mutate data, send messages, browse external content, access credentials indirectly, or operate autonomously. Covers tool schemas, policy engines, prompt injection, action authorization, human approval, output validation, loop/cost budgets, and auditability.