Audit and harden input validation, boundary checking, and sanitization across FastAPI Pydantic schemas and React form inputs. Use whenever adding a new API endpoint or form field, when the user asks to check for injection risks, malformed input handling, schema abuse, oversized payloads, or "what happens if someone sends garbage/malicious input here." Also trigger when reviewing file/CSV/bulk-upload endpoints, since these are the highest-risk input surfaces in a placement system (resume uploads, bulk student import, CGPA/backlog numeric fields).