The uncomfortable thing about prompt-based safety is that the model keeps reading the prompt after the moment you meant it to apply. OpenClaw issue #95773 is a clean example: Task Guard tells the model that the final reply for the turn “must be and can only be NO_REPLY,” then