Single log tag for all consumer-facing library output. Filter on this in the host app — internal component names are not exposed.
Forwards sanitized library lifecycle messages to the host sink. Wire payloads, URLs, and tokens are redacted before log is invoked. log always receives TAG as the tag argument.