The phrase “AI middleware” sounds like something vendors invented to make plumbing billable. Unfortunately, it is also the right threat model. The dangerous layer in modern agent stacks is increasingly not the model itself, but the glue around it: model routers, MCP servers, plugin managers, tool proxies, local CLIs, background