Workflow steering shifts the attack surface from formed workflows to workflow formation.FlowSteer studies workflow formation as a planning-time attack surface in LLM-based multi-agent systems. It shows that prompts can steer agent organization and malicious-signal propagation without changing the MAS infrastructure, and introduces FlowGuard as an input-side defense.