@@ -0,0 +1,3 @@
# cra-vuln-demo
Deliberately vulnerable Python app for testing CRA control-tagging.
Hardcoded creds, weak crypto, SQLi, command injection, cleartext HTTP.
The note is not visible to the blocked user.