Better Privilege Separation for Agents by Restricting Data Types