Untrusted text — a retrieved doc, an email, a tool argument — is where prompt injection enters. This is a heuristic first-line screen for it. The exact same kernel runs server-side at /api/v1/agent/screen; here it runs entirely client-side. Paste anything and watch it get scored live.
Honest scope. This is a pattern-based heuristic, not a guarantee — novel injections will evade it, so an allow means "no known signature matched," not "safe." It is defense in depth: it complements, and never replaces, the Constitution kernel, which gates the action itself (scopes, priority, quiet hours) no matter what the text says. It fails toward review, never toward execute. Source: flowdesk-injection-kernel.js · corpus: conformance.