With the attack surface established, executed a series of manual techniques through Burp's Repeater and Intruder tools, including prompt injection, system prompt extraction, role and system-message injection, parameter manipulation, error-message disclosure, and authentication testing. Demonstrated additional Burp capabilities relevant to AI systems, including response comparison to prove behavioral changes under attack, randomness testing of server-generated identifiers, and live request tampering to illustrate a man-in-the-middle scenario against AI traffic.