The lethal trifecta for AI agents private data untrusted content and external communication