Prompt injection usually gets framed as something the outside world does to an agent: a malicious README, a poisoned web page, a hostile GitHub issue, a tool description with a little policy grenade hidden inside. The latest Claude Code role-boundary report is more uncomfortable because the alleged poison pill comes