> Injection-resistant by mandate
> Memory is attacker-controllable input. The spec requires a verify, filter, frame rehydration pipeline. Never string-interpolated into the prompt.
Uhhh... so who wants to tell them how LLMs work?