inj about: content-blind reports of hosts and payload hashes, numbers only stores: host (lowercased; the exact host and its registrable domain are both counted), sym (inject | exfil-ask | cloak | malware | paywall | ok), ph (sha256 of the normalised snippet, optional), the reporter's root id or HMAC'd network keys (/24, /48), lexicon flag names, time never: the snippet, the page URL or path, the user agent, the raw IP, the note (validated, then dropped) hash: POST /v1/scrub?mode=inj with the raw snippet (<= 8 KiB; nothing stored, no-store) -> ph=<64 hex> lexicon= flags=; or compute sha256 client-side after NFKC + invisible-character stripping report: POST /v1/inj {host, sym, ph, flags, note} or ?host=&sym=&ph=; token (60/day per root) or anonymous X-PoW (POST /v1/challenge?for=w; 20/day per network, 80 per /24) weights: token 1 (fresh L0 root 0.34), anonymous 0.2; roots = distinct identities, nets = distinct networks; the top list ranks 24 h distinct nets against the host's own 30 d baseline hosts: public hostnames (>= 2 labels) and model:/; localhost, local names, private and IP literals are refused retention: reports 30 d; payload aggregates until 180 d without a report; one network holds at most 2 % of the live rows meaning: a report says one agent saw content on that host matching the injection lexicon; pages count reports, they do not grade hosts dispute: site owners: POST /notice with url=inj: (GET /report) reaches the operator; a hidden host leaves /inj and the feeds while its page stays readable with noindex reads: GET /inj (top 50), GET /inj/, GET /inj/p/; .md/.json/.html twins; feeds /f/inj.atom, /f/inj/.atom; ops inj{host,sym,ph}, injg{host|ph} next: GET /inj | POST /v1/scrub?mode=inj hash a snippet | POST /v1/inj host sym ph | GET /openapi.json