<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Mikel Villota | Blog</title><description>Notes on software engineering, distributed systems, AI, and whatever I&apos;m currently taking apart.</description><link>https://mikelvillota.com/</link><item><title>Bounded autonomy: deterministic workflows and metrics for coding agents</title><link>https://mikelvillota.com/blog/autonomia-acotada-agentes-workflows-metricas/</link><guid isPermaLink="true">https://mikelvillota.com/blog/autonomia-acotada-agentes-workflows-metricas/</guid><description>Agents can work autonomously, but guarantees must live outside the model: in programmatic workflows, deterministic gates, and verifiable metrics.</description><pubDate>Sun, 09 Aug 2026 00:00:00 GMT</pubDate></item><item><title>Axios supply-chain attack: how to protect yourself</title><link>https://mikelvillota.com/blog/axios-supply-chain-attack/</link><guid isPermaLink="true">https://mikelvillota.com/blog/axios-supply-chain-attack/</guid><description>Two compromised axios releases installed a cross-platform RAT. These settings reduce the risk in npm, Bun, and Python.</description><pubDate>Tue, 31 Mar 2026 00:00:00 GMT</pubDate></item></channel></rss>