usestrix PyPI system_prompt.jinja inclusion of functionality from untrusted control sphere (CVE-2026-15519) | HOL Guard CVE