<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Builder Journal on Rex Coleman</title><link>https://rexcoleman.dev/categories/builder-journal/</link><description>Securing AI from the architecture up. Research, tools, and methodology for AI security. Creator of govML.</description><image><title>Rex Coleman</title><url>https://rexcoleman.dev/images/og-default.png</url><link>https://rexcoleman.dev/images/og-default.png</link></image><generator>Hugo</generator><language>en-us</language><lastBuildDate>Thu, 19 Mar 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://rexcoleman.dev/categories/builder-journal/index.xml" rel="self" type="application/rss+xml"/><item><title>AI Security Has a Shipping Problem</title><link>https://rexcoleman.dev/posts/ai-security-shipping-problem/</link><pubDate>Thu, 19 Mar 2026 00:00:00 +0000</pubDate><guid>https://rexcoleman.dev/posts/ai-security-shipping-problem/</guid><description>The AI security industry produces frameworks and guidelines but almost no one ships working tools that practitioners can deploy today.</description></item><item><title>The Agent Security Gap Nobody's Talking About: Skills Run Every Heartbeat</title><link>https://rexcoleman.dev/posts/agent-security-gap-skills/</link><pubDate>Thu, 19 Mar 2026 00:00:00 +0000</pubDate><guid>https://rexcoleman.dev/posts/agent-security-gap-skills/</guid><description>Everyone&amp;#39;s worried about prompt injection, but the real agent attack surface is third-party skills — they execute persistently on every heartbeat cycle.</description></item><item><title>How I Govern AI-Assisted ML Projects</title><link>https://rexcoleman.dev/posts/govml-methodology/</link><pubDate>Sat, 14 Mar 2026 00:00:00 +0000</pubDate><guid>https://rexcoleman.dev/posts/govml-methodology/</guid><description>I built a governance framework for ML projects after watching 14 manual audit cycles nearly break my workflow. Here&amp;#39;s how govML works and why governance-as-code is the only way to scale ML research.</description></item></channel></rss>