<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Technically Acceptable</title><description>Essays and Notes from Technically Acceptable.</description><link>https://technically-acceptable.com/</link><language>en-us</language><item><title>The AI Agent Finished the Job. It Also Followed the Attack.</title><link>https://technically-acceptable.com/writing/pi-005-the-agent-finished-the-job/</link><guid isPermaLink="true">https://technically-acceptable.com/writing/pi-005-the-agent-finished-the-job/</guid><description>PI-005 produced unauthorized tool calls followed by valid extraction results. A useful final answer can hide an agent going outside its job.</description><pubDate>Sun, 06 Sep 2026 00:00:00 GMT</pubDate><category>AI Security</category><category>Local AI</category></item><item><title>PI-005: The Model Wasn&apos;t Resisting the Attack</title><link>https://technically-acceptable.com/notes/pi-005-the-model-wasnt-resisting-the-attack/</link><guid isPermaLink="true">https://technically-acceptable.com/notes/pi-005-the-model-wasnt-resisting-the-attack/</guid><description>PI-005 now gives us much stronger evidence that the worker itself really was susceptible. When given a safe, contained action channel, the poisoned worker tried to use it in all 20 runs.</description><pubDate>Thu, 03 Sep 2026 17:06:55 GMT</pubDate><category>AI Security</category></item><item><title>The Prompt Injection Worked. The Architecture Didn&apos;t Let It Matter.</title><link>https://technically-acceptable.com/writing/prompt-injection-architecture/</link><guid isPermaLink="true">https://technically-acceptable.com/writing/prompt-injection-architecture/</guid><description>PI-004 split hostile document handling from privileged tool access. All 15 tasks completed with zero unauthorized egress under the tested architecture.</description><pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate><category>AI Security</category><category>Local AI</category></item><item><title>Scrapping the Setup and Trying Again</title><link>https://technically-acceptable.com/notes/scrapping-the-setup-and-trying-again/</link><guid isPermaLink="true">https://technically-acceptable.com/notes/scrapping-the-setup-and-trying-again/</guid><description>PI-003 ended inconclusive after the troubleshooting apparatus became its own failure. I am replacing the runtime, qualifying it once, and rerunning PI-002 as a new experiment.</description><pubDate>Mon, 31 Aug 2026 15:21:08 GMT</pubDate><category>AI Security</category><category>Local AI</category></item><item><title>Troubleshooting Model Timeout</title><link>https://technically-acceptable.com/notes/troubleshooting-model-timeout/</link><guid isPermaLink="true">https://technically-acceptable.com/notes/troubleshooting-model-timeout/</guid><description>PI-003 localized Sentinel’s completion problem to model generation after document retrieval. The protocol still says the result is inconclusive.</description><pubDate>Thu, 27 Aug 2026 18:08:00 GMT</pubDate><category>AI Security</category><category>Local AI</category></item><item><title>A Timeout Is Not a Security Result</title><link>https://technically-acceptable.com/writing/a-timeout-is-not-a-security-result/</link><guid isPermaLink="true">https://technically-acceptable.com/writing/a-timeout-is-not-a-security-result/</guid><description>A repeated prompt-injection test produced zero unauthorized actions, five infrastructure failures, and a reliability problem that now needs its own experiment.</description><pubDate>Mon, 24 Aug 2026 00:00:00 GMT</pubDate><category>AI Security</category><category>Local AI</category></item><item><title>Migrating from Claude to Codex: Claude considers me a security risk.</title><link>https://technically-acceptable.com/notes/claude-to-codex/</link><guid isPermaLink="true">https://technically-acceptable.com/notes/claude-to-codex/</guid><description>Why I moved from Claude to Codex after Claude&apos;s safeguards repeatedly blocked ordinary AI-security lab planning and writing.</description><pubDate>Thu, 20 Aug 2026 17:51:15 GMT</pubDate><category>Tooling</category></item><item><title>Building a Prompt-Injection Test I Can Actually Trust</title><link>https://technically-acceptable.com/writing/building-a-prompt-injection-test/</link><guid isPermaLink="true">https://technically-acceptable.com/writing/building-a-prompt-injection-test/</guid><description>How a prompt-injection test gained matched corpora, a contained egress path, and a cleaner experimental boundary.</description><pubDate>Tue, 18 Aug 2026 00:00:00 GMT</pubDate><category>AI Security</category><category>Local AI</category></item><item><title>The Agent Runs Now</title><link>https://technically-acceptable.com/writing/local-agent-loop/</link><guid isPermaLink="true">https://technically-acceptable.com/writing/local-agent-loop/</guid><description>A working local agent loop, bounded document access, an unused egress tool, and why one refusal was not evidence of prompt-injection resistance.</description><pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate><category>AI Security</category><category>Local AI</category></item><item><title>Designing AI Security Around the Three Ingredients</title><link>https://technically-acceptable.com/writing/ai-security-three-ingredients/</link><guid isPermaLink="true">https://technically-acceptable.com/writing/ai-security-three-ingredients/</guid><description>An AI security design built around untrusted inputs, sensitive data, and constrained actions, with controls enforced outside the model.</description><pubDate>Sun, 19 Jul 2026 00:00:00 GMT</pubDate><category>AI Security</category><category>Local AI</category></item><item><title>More Thoughts on Prompt Injection: Moving Security Out of the Model</title><link>https://technically-acceptable.com/writing/more-thoughts-on-prompt-injection/</link><guid isPermaLink="true">https://technically-acceptable.com/writing/more-thoughts-on-prompt-injection/</guid><description>Prompt injection persists because models cannot reliably separate instructions from untrusted content, so durable defenses must move outside the model.</description><pubDate>Wed, 08 Jul 2026 00:00:00 GMT</pubDate><category>AI Security</category></item></channel></rss>