* fix(security): screen engine-ingested external text for prompt injection
The X mentions poll and the vault inbox both fed attacker-writable text
(tweets, tagged notes incl. meeting-bridge output) raw into local-model
prompts and CEO-facing draft payloads. The agent-sdk prompt guard's
detection moves to a pure roboco/foundation/policy/injection_guard.py
(prompt_guard re-exports it — grok path byte-identical) and gains
screen_external_text: per-line detection where a matched line is flagged
in place, never dropped, and the whole text rides an explicit
untrusted-content envelope. Both engines screen once at ingestion and
use the screened rendering for the model prompt AND the persisted
marker/description — including the vault engine's deterministic
LLM-failure fallback, which previously used the raw body verbatim.
* chore(docs): reflow hard-wrapped prose inherited from the six-PR merge train
* chore(foundation): regenerate lifecycle artifacts; reflow inherited prose
---------
Co-authored-by: Renn F <rennf93@users.noreply.github.com>