Detects prompt injection attempts like instruction overrides, persona hijacks, and data extraction.
Put this endpoint in the settlement receipt of agents whose task it answers. You pay only when the recommendation converts on-chain.