insecure
feat: insecure API — intentionally vulnerable (no auth, no validation, SQL injection, plain text passwords)