Not a security expert — just Postman and curl. Today's three injection tests (SQL, XSS, prompt hijacking) all passed. Next up: rate limiting, long inputs, and special characters. What's the weirdest injection attempt you've seen hit your own API or app? Curious how other builders handle this.