<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Sean McQuilling</title><description>Cybersecurity, agentic AI, and local agent field notes.</description><link>https://seanmcquilling.com/</link><language>en-us</language><item><title>Using MITRE ATLAS to Make AISecOps Threat-Informed</title><link>https://seanmcquilling.com/blog/mitre-atlas-for-aisecops/</link><guid isPermaLink="true">https://seanmcquilling.com/blog/mitre-atlas-for-aisecops/</guid><description>MITRE ATLAS gives AI security teams a shared map of adversary behavior for threat modeling, detection engineering, red teaming, and incident response.</description><pubDate>Sat, 18 Jul 2026 16:30:00 GMT</pubDate></item><item><title>Using OWASP&apos;s Agentic Top 10 to Govern Systems That Act</title><link>https://seanmcquilling.com/blog/owasp-agentic-top-10-for-aisecops/</link><guid isPermaLink="true">https://seanmcquilling.com/blog/owasp-agentic-top-10-for-aisecops/</guid><description>The OWASP Agentic Top 10 moves security beyond model output and into goals, tools, identities, memory, delegation, and runtime control.</description><pubDate>Sat, 18 Jul 2026 16:20:00 GMT</pubDate></item><item><title>Using the OWASP LLM Top 10 as an Engineering Baseline</title><link>https://seanmcquilling.com/blog/owasp-llm-top-10-for-aisecops/</link><guid isPermaLink="true">https://seanmcquilling.com/blog/owasp-llm-top-10-for-aisecops/</guid><description>The OWASP LLM Top 10 turns common language-model failure modes into security requirements, tests, telemetry, and response plans.</description><pubDate>Sat, 18 Jul 2026 16:10:00 GMT</pubDate></item><item><title>Using NIST AI RMF to Build an AISecOps Program</title><link>https://seanmcquilling.com/blog/nist-ai-rmf-for-aisecops/</link><guid isPermaLink="true">https://seanmcquilling.com/blog/nist-ai-rmf-for-aisecops/</guid><description>NIST AI RMF gives an AI security program its operating model: govern the work, map the context, measure the risk, and manage what happens next.</description><pubDate>Sat, 18 Jul 2026 16:00:00 GMT</pubDate></item><item><title>Zero Trust Is the Foundation AI Agents Need</title><link>https://seanmcquilling.com/blog/zero-trust-is-the-foundation-ai-agents-need/</link><guid isPermaLink="true">https://seanmcquilling.com/blog/zero-trust-is-the-foundation-ai-agents-need/</guid><description>Anthropic&apos;s framework connects agent identity, least agency, tool boundaries, memory integrity, and recovery into one practical security model.</description><pubDate>Sat, 18 Jul 2026 15:30:00 GMT</pubDate></item><item><title>A Feature Is Not Shipped Until It Works</title><link>https://seanmcquilling.com/blog/a-feature-is-not-shipped-until-it-works/</link><guid isPermaLink="true">https://seanmcquilling.com/blog/a-feature-is-not-shipped-until-it-works/</guid><description>Four failures in Aria&apos;s voice input taught me why a green build and a working development demo are not enough.</description><pubDate>Thu, 16 Jul 2026 18:00:00 GMT</pubDate></item><item><title>When Agent Autonomy Produces Activity Instead of Work</title><link>https://seanmcquilling.com/blog/when-agent-autonomy-produces-activity/</link><guid isPermaLink="true">https://seanmcquilling.com/blog/when-agent-autonomy-produces-activity/</guid><description>An audit of Aria&apos;s autonomous loop found hundreds of goals, almost no progress, and a completion system that rewarded plausible output.</description><pubDate>Thu, 16 Jul 2026 17:00:00 GMT</pubDate></item><item><title>Your Research Agent Needs a Consumer</title><link>https://seanmcquilling.com/blog/research-agents-need-a-consumer/</link><guid isPermaLink="true">https://seanmcquilling.com/blog/research-agents-need-a-consumer/</guid><description>Aria produced hundreds of useful research reports that nothing ever read. The fix was a small, idempotent consumer pipeline.</description><pubDate>Thu, 16 Jul 2026 16:00:00 GMT</pubDate></item><item><title>The Observer Changes the Agent</title><link>https://seanmcquilling.com/blog/the-observer-changes-the-agent/</link><guid isPermaLink="true">https://seanmcquilling.com/blog/the-observer-changes-the-agent/</guid><description>A self-observation feature for Aria showed why metrics should remain available without becoming permanent instructions.</description><pubDate>Thu, 16 Jul 2026 15:00:00 GMT</pubDate></item><item><title>The Bigger Model Lost the Bakeoff</title><link>https://seanmcquilling.com/blog/the-bigger-model-lost-the-bakeoff/</link><guid isPermaLink="true">https://seanmcquilling.com/blog/the-bigger-model-lost-the-bakeoff/</guid><description>What two rounds of testing Aria&apos;s language and image models taught me about speed, benchmarks, and knowing when a score is wrong.</description><pubDate>Thu, 16 Jul 2026 00:00:00 GMT</pubDate></item><item><title>The Fourth-Agent Test</title><link>https://seanmcquilling.com/blog/agentic-ai-field-notes/</link><guid isPermaLink="true">https://seanmcquilling.com/blog/agentic-ai-field-notes/</guid><description>A quick way to tell whether your agent setup is ready to grow or still held together by one-off fixes.</description><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate></item><item><title>Threat Modeling the Agent on Your Laptop</title><link>https://seanmcquilling.com/blog/security-notes-for-local-agents/</link><guid isPermaLink="true">https://seanmcquilling.com/blog/security-notes-for-local-agents/</guid><description>A practical security review for agents that can read files, run commands, and use outside services.</description><pubDate>Mon, 15 Jun 2026 00:00:00 GMT</pubDate></item><item><title>A Small Pattern Library for Tool-Calling Agents</title><link>https://seanmcquilling.com/blog/pattern-library-for-tool-calling/</link><guid isPermaLink="true">https://seanmcquilling.com/blog/pattern-library-for-tool-calling/</guid><description>Four simple work patterns for agents that use tools, make changes, test the result, and recover from interruptions.</description><pubDate>Sun, 14 Jun 2026 00:00:00 GMT</pubDate></item></channel></rss>