promptdojo_

Train/inference skew — step 4 of 7

Complete defense #1: ONE normalize implementation, with the fitted stats saved and passed to both paths.