A deterministic tool-call gateway that tracks value provenance stops 99.3% of prompt-injection attacks on AgentDojo, outperforming three open classifiers despite requiring human approval in ~29% of legitimate tasks. The gateway's architectural approach proves more robust than detection-based classifiers against obfuscated injections, though it struggles when attacker data is already in trusted graphs and cannot prevent data exfiltration through output channels.