defense-in-depth 1 The Read-Only Triage Agent Pattern: Architectural Defense Against Prompt Injection Feb 15, 2026