Defending against indirect prompt injection in agentic ai