<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Relm Journal</title>
    <link>https://relmhq.com/blog/</link>
    <description>Field notes on autonomous agents.</description>
    <language>en</language>
    <atom:link href="https://relmhq.com/feed.xml" rel="self" type="application/rss+xml"/>

    <!-- Newest first. Add an item here when a post ships; see also sitemap.xml. -->
    <item>
      <title>Claude Code's Auto Mode is not a security boundary</title>
      <link>https://relmhq.com/blog/auto-mode-is-not-a-security-boundary/</link>
      <guid isPermaLink="true">https://relmhq.com/blog/auto-mode-is-not-a-security-boundary/</guid>
      <pubDate>Sun, 09 Aug 2026 09:00:00 +0000</pubDate>
      <description>On August 14, Auto Mode becomes the default in Claude Code: a model reviews each command instead of a human approving it. It caught 89% of dangerous commands in testing; humans caught 13.6%. That is a real improvement, and it is still not a security boundary.</description>
    </item>

    <item>
      <title>Three coding-agent incidents, three different failures</title>
      <link>https://relmhq.com/blog/three-incidents-three-failures/</link>
      <guid isPermaLink="true">https://relmhq.com/blog/three-incidents-three-failures/</guid>
      <pubDate>Sat, 30 May 2026 09:00:00 +0000</pubDate>
      <description>Three high-profile coding-agent incidents from the past two months — a Cursor agent deleting a production database, a Gemini agent exfiltrating a token after prompt injection, and an npm supply-chain compromise — and why they don't collapse into a single problem.</description>
    </item>
  </channel>
</rss>
