Article 1 unplug-tiny: a 22M-parameter prompt-injection firewall that tells you *where* the attack is