A car dealership’s chatbot once agreed to sell a $76,000 SUV for a single dollar. All it took was a sentence typed into a chat box, no code, no exploit, no technical skill. That’s prompt injection: the number one vulnerability on the OWASP Top 10 for LLM Applications, a position it’s held since the list’s …