<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Paul MK — Writing</title>
    <link>https://paulappsec-site.paulmk2143.workers.dev/writing</link>
    <atom:link href="https://paulappsec-site.paulmk2143.workers.dev/rss.xml" rel="self" type="application/rss+xml" />
    <description>Software engineer and application security. I build production multi-tenant and payment systems, then attack them across tenant boundaries, webhooks and authorization paths.</description>
    <language>en</language>
    <item>
      <title>I wrote four Semgrep rules and never ran them. Two were broken.</title>
      <link>https://paulappsec.hashnode.dev/semgrep-rules-i-never-ran</link>
      <guid isPermaLink="true">https://paulappsec.hashnode.dev/semgrep-rules-i-never-ran</guid>
      <pubDate>Mon, 17 Aug 2026 00:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>
