New prompt injection papers Agents Rule of Two and The Attacker Moves Second