Hijacking Windsurf: How Prompt Injection Leaks Developer Secrets | AI Sec Watch