<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Riad Mukhtarov — Writing</title>
    <link>https://riad.cc/writing/</link>
    <description>Notes on the parts of a system that have to stay honest when nobody is checking.</description>
    <language>en</language>
    <atom:link href="https://riad.cc/rss.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Assume the model cooperates with the attacker</title>
      <link>https://riad.cc/writing/assume-the-model-cooperates-with-the-attacker/</link>
      <guid isPermaLink="true">https://riad.cc/writing/assume-the-model-cooperates-with-the-attacker/</guid>
      <description>An AI agent runs shell commands that did not exist until a prompt asked for them. You cannot write a static policy for code that has not been written yet — so the containment has to hold even when the model is talked into helping.</description>
      <pubDate>Sun, 02 Aug 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>The model doesn&apos;t get the last word</title>
      <link>https://riad.cc/writing/the-model-doesnt-get-the-last-word/</link>
      <guid isPermaLink="true">https://riad.cc/writing/the-model-doesnt-get-the-last-word/</guid>
      <description>A language model writes the verdict in my prior-art CLI. It is structurally incapable of telling me the coast is clear when it is not — and that guarantee lives in the type system, not the prompt.</description>
      <pubDate>Sat, 01 Aug 2026 00:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>
