Tag
A risk signal, not a control: weighted checks via a maintained library, a launch gate, and server-side enforcement so the block is not theater.