Armorer Guard is interesting less because it says “prompt injection” and more because of where it wants to sit. The project is a local Rust scanner for prompts, retrieved content, model output, tool-call arguments, memory writes, logs, and outbound messages. In other words, it is trying to live at the