drop pdf / docx / image · detect known prompt-injection payload patterns · runs locally
pdf · docx · txt export · local only
heuristic screener · vendor schema varies · not definitive proof