pub fn is_suspicious_instruction(content: &str) -> InjectionProbeExpand description
Static, regex-based prompt-injection probe.
This is intentionally lightweight and deterministic — it does not call any model. It exists so the harness can:
- Record
prompt_injection_flagged = trueon the audit entry. - Surface a small annotation inside the fence so the system prompt can remind the model to be careful without silent redaction.