Treating prompt injection as intrinsic and then asking what a hijacked plan has to get through is the right way round, and it is the framing most agent-security writing gets backwards by starting at the prompt.
Putting the tool broker outside the model is the load-bearing piece, because it is the only control that still holds when the model is fully compromised.
One addition to the egress plane: deny-by-default is necessary, but the allowlist erodes, and every allowed domain is an exfiltration channel for anything the agent can read. Worth reviewing that list on a schedule rather than only at the moment something gets added to it.