Screen untrusted text against known prompt-injection patterns (pattern matching, not a model). Returns which named patterns matched.