Why it matters: Agent firewalls see attacks buried in tool outputs, not clean benchmark strings, so default detector settings can give false confidence.
How to apply: Re-run your detector on real tool-output payloads, tune the decision threshold, and keep a local CPU-only eval set before shipping an agent gate.