Unplug is agent runtime security for LLM applications. It tracks where text came from (user vs retrieved vs tool output), scans for prompt injection and destructive actions, and enforces tool-call policy, with span-level redaction instead of binary blocking. Most guardrails nuke the whole message. Unplug finds the exact attack span and surgically removes it, keeping the rest usable.