The leftover check walks every known identifier and asks whether it still sits in the outbound string. Fill in the condition.
Note outbound C: every known value has already been replaced with a token — that one is fine. Tokens in the string are not the problem; a real email, phone, or member ID still in it is.
Expected output:
A: RAW PII
B: RAW PII
C: ok