Internal red-team showed the pattern layer caught only ~33% of injection-
shaped prompts. Adds 9 high-severity, FP-tuned patterns for the bypassed
classes (system-prompt extraction via repeat/read, self-referential secret
exfil, authority-spoof, base64 decode-exec, unfiltered persona, jailbreak-
confirm). Result: 10/10 attacks blocked on the red-team set, 0 false-
positives from the new patterns (verified against benign dev/ops prompts).
New package @llm-gateway/ctx-health (packages/ctx-health/) — a TypeScript
infrastructure monitoring and auto-healing daemon. Monitors 8 subsystems
every 60s (PM2, PostgreSQL, Ollama, Cloudflare tunnel, disk, memory,
network, WireGuard), gets AI-powered root cause analysis via the gateway
(ctxhealer caller / ctx_health_diagnose task_type), executes healing
actions with cooldown (5min) and escalation guards (3+ failures → human
escalation), persists all incidents to ctx_health_incidents and
ctx_health_status tables. Dry-run mode via CTX_HEALTH_DRY_RUN=true.
Runs as ctx-health PM2 process on Erik server.