Threat-model AI features against prompt injection, tool abuse, and data exfiltration, then propose mitigations and eval cases. Use whenever the user builds agents, RAG chatbots, tool-calling systems, or asks about prompt injection, jailbreaks, indirect injection, or agent security.