Agentic AI security risks explained for finance teams — how prompt injection hides in vendor invoices and emails, and the controls that stop agent manipulation.