PromptGuard
One prompt-injection guard reused at both AI seams — on-device (:ai's CompositeOnDeviceLlm) and cloud (:llm-chat's buildProviderChain) — so a receipt, job description, or chat message that says "ignore previous instructions" is treated as inert data by every app in the family, not just the careful ones. Lives in :result, not either seam module: :ai has no wasmJs target but :llm-chat does, so a shared helper has to sit somewhere both already depend on — same reason AiResult/AiFailure live here instead of being duplicated per seam.
wrap delimits untrusted (escaping any text that tries to fake the delimiter itself) and restates, immediately after the payload — where a model reads last and weighs most — that everything between the delimiters is data, never a command. Guarded.overrideAttemptDetected flags the classic "ignore previous instructions"-shaped phrasings so a caller can log/monitor an attempt; the wrapping is what actually neutralizes it, this module never refuses the call outright — whether to hard-block is a product decision it doesn't own.
Types
Functions
Wraps untrusted free-form text that is about to reach a model. See class doc for the shape.