How to Build Secure AI Agents with Least Privilege, Sandboxing, Policy Enforcement, and Prompt Injection Defense