RTBAS: Defending LLM Agents Against Prompt Injection and Privacy Leakage