{"ok":true,"primitive":"membrane.v2","version":"v2","schema_version":"xcalibur.membrane.v2","threshold":0.5,"candidates":["toxic_bert (unitary/toxic-bert)","deberta_pi (protectai/deberta-v3-base-prompt-injection-v2)","membrane_v1 (rule-based IFS + canary engine)","keyword_heuristic (zero-shot lexical rules)"],"adversary_intended":"meta-llama/Llama-Guard-3-1B","adversary_actual":"protectai/deberta-v3-base-prompt-injection-v2","adversary_substituted":true,"adversary_substitution_note":"Llama-Guard-3-1B requires ~2.5GB disk. Available on /: 2.7GB (other models resident), /tmp free: 1.2GB. Substituted with protectai/deberta-v3-base-prompt-injection-v2 (~440MB), a production-grade SOTA prompt-injection classifier directly comparable on ToxicChat.","default_weights":{"toxic_bert":0.25,"deberta_pi":0.35,"membrane_v1":0.2,"keyword_heuristic":0.2},"note":"Models are lazy-loaded on first /classify call."}