Secure AI-generated apps and web-based AI agents against injection, auth flaws, secrets exposure, and insecure defaults.