New prompt injection papers: Agents rule of two and the attacker moves second | Not Hacker News!