
5 fully detailed projects that go deeper than the general OWASP API Top 10 sweep already covered by the "API Security Testing Framework" project in the AppSec Engineering doc. That project is broad coverage; these five are specialist deep-dives (JWT, GraphQL, shadow APIs, rate limiting, gateway hardening) — position them as the "advanced" API security track for students who've already done the Top 10 sweep, or as standalone specialist projects for anyone targeting API-security-heavy roles.