<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Field Notes — Omar Badran</title>
    <link>https://omarbadran.dev/blog</link>
    <atom:link href="https://omarbadran.dev/feed.xml" rel="self" type="application/rss+xml"/>
    <description>Notes on AI engineering, application security, DevSecOps and Arabic-first web development, by Omar Badran.</description>
    <language>en</language>
    <lastBuildDate>Tue, 28 Jul 2026 09:00:00 GMT</lastBuildDate>
    <managingEditor>contact@omarbadran.dev (Omar Badran)</managingEditor>
    <webMaster>contact@omarbadran.dev (Omar Badran)</webMaster>
    <image>
      <url>https://omarbadran.dev/og-image.png</url>
      <title>Field Notes — Omar Badran</title>
      <link>https://omarbadran.dev/blog</link>
    </image>
    <item>
      <title>Ollama: Run Real Models on Your Own Machine</title>
      <link>https://omarbadran.dev/blog/ollama-local-models</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/ollama-local-models</guid>
      <pubDate>Tue, 28 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Engineering</category>
      <description>One command pulls a model and serves it on localhost. For prototyping, private data, and never paying per token again.</description>
      <enclosure url="https://omarbadran.dev/img/blog/ollama-local-models.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>Turn Your Workflow Into a Claude Skill</title>
      <link>https://omarbadran.dev/blog/claude-code-skills</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/claude-code-skills</guid>
      <pubDate>Fri, 24 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Engineering</category>
      <description>Prompting the same instructions every session is a waste. A skill is a folder that teaches the model how you work — once — and it pays back on every project after that.</description>
      <enclosure url="https://omarbadran.dev/img/blog/claude-code-skills.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>llama.cpp and the Quantization You Actually Need</title>
      <link>https://omarbadran.dev/blog/llama-cpp-quantization</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/llama-cpp-quantization</guid>
      <pubDate>Tue, 21 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Engineering</category>
      <description>Q4, Q5, Q8 — the difference between a model that fits your GPU and one that does not, explained without the maths.</description>
      <enclosure url="https://omarbadran.dev/img/blog/llama-cpp-quantization.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>Building a Subagent Team That Reviews Its Own Work</title>
      <link>https://omarbadran.dev/blog/subagent-team</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/subagent-team</guid>
      <pubDate>Fri, 17 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Engineering</category>
      <description>One agent writing code is autocomplete. Several specialists who critique and correct each other is a process — and the difference shows up in the diff.</description>
      <enclosure url="https://omarbadran.dev/img/blog/subagent-team.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>vLLM: When You Outgrow One Request at a Time</title>
      <link>https://omarbadran.dev/blog/vllm-serving-throughput</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/vllm-serving-throughput</guid>
      <pubDate>Tue, 14 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Engineering</category>
      <description>Continuous batching and paged attention are why a serving stack handles fifty concurrent users on hardware that choked on five.</description>
      <enclosure url="https://omarbadran.dev/img/blog/vllm-serving-throughput.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>Writing a CLAUDE.md the Model Actually Follows</title>
      <link>https://omarbadran.dev/blog/claude-md-that-works</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/claude-md-that-works</guid>
      <pubDate>Thu, 09 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Engineering</category>
      <description>Most project instruction files are wish lists. The ones that work read like a senior engineer briefing a new hire on day one — specific, ordered, and short.</description>
      <enclosure url="https://omarbadran.dev/img/blog/claude-md-that-works.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>Open WebUI: A Chat Front-End Your Client Can Actually Use</title>
      <link>https://omarbadran.dev/blog/open-webui-chat-ui</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/open-webui-chat-ui</guid>
      <pubDate>Tue, 07 Jul 2026 09:00:00 GMT</pubDate>
      <category>AI Engineering</category>
      <description>Local models are useless to a business until someone non-technical can talk to them. This is the missing half.</description>
      <enclosure url="https://omarbadran.dev/img/blog/open-webui-chat-ui.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>Your Portfolio Is a Product, Not a Gallery</title>
      <link>https://omarbadran.dev/blog/portfolio-that-converts</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/portfolio-that-converts</guid>
      <pubDate>Tue, 30 Jun 2026 09:00:00 GMT</pubDate>
      <category>Design</category>
      <description>A grid of screenshots tells a client what you touched. A case study tells them what you decided — and decisions are the only thing they are actually buying.</description>
      <enclosure url="https://omarbadran.dev/img/blog/portfolio-that-converts.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>Whisper: Transcription That Handles Arabic</title>
      <link>https://omarbadran.dev/blog/whisper-speech-to-text</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/whisper-speech-to-text</guid>
      <pubDate>Tue, 30 Jun 2026 09:00:00 GMT</pubDate>
      <category>AI Engineering</category>
      <description>Most speech-to-text falls apart on Arabic dialects. Here is what actually works, and where it still struggles.</description>
      <enclosure url="https://omarbadran.dev/img/blog/whisper-speech-to-text.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>ComfyUI: Image Generation as a Pipeline, Not a Prompt Box</title>
      <link>https://omarbadran.dev/blog/comfyui-node-pipelines</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/comfyui-node-pipelines</guid>
      <pubDate>Tue, 23 Jun 2026 09:00:00 GMT</pubDate>
      <category>AI Engineering</category>
      <description>Nodes and graphs look intimidating until you need the same result twice. Then they are the only sane option.</description>
      <enclosure url="https://omarbadran.dev/img/blog/comfyui-node-pipelines.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>Arabic-First, Not Arabic-Translated</title>
      <link>https://omarbadran.dev/blog/rtl-first-arabic</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/rtl-first-arabic</guid>
      <pubDate>Sun, 21 Jun 2026 09:00:00 GMT</pubDate>
      <category>Design</category>
      <description>Flipping a layout to RTL is twenty minutes of CSS. Making an Arabic interface feel native is a different job entirely — and users notice the gap immediately.</description>
      <enclosure url="https://omarbadran.dev/img/blog/rtl-first-arabic.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>Aider: AI Pair Programming That Commits</title>
      <link>https://omarbadran.dev/blog/aider-terminal-pair</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/aider-terminal-pair</guid>
      <pubDate>Tue, 16 Jun 2026 09:00:00 GMT</pubDate>
      <category>AI Engineering</category>
      <description>It edits your repo and writes the commit message. Which is either exactly what you want or a very good reason to work on a branch.</description>
      <enclosure url="https://omarbadran.dev/img/blog/aider-terminal-pair.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>Owning Your Own Name in Search</title>
      <link>https://omarbadran.dev/blog/own-your-name-seo</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/own-your-name-seo</guid>
      <pubDate>Fri, 12 Jun 2026 09:00:00 GMT</pubDate>
      <category>SEO</category>
      <description>If someone searches your name after a meeting, whatever they find becomes your reference check. Here is the exact stack I used to make sure they find me.</description>
      <enclosure url="https://omarbadran.dev/img/blog/own-your-name-seo.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>Continue: An Open-Source Coding Assistant You Control</title>
      <link>https://omarbadran.dev/blog/continue-dev-assistant</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/continue-dev-assistant</guid>
      <pubDate>Tue, 09 Jun 2026 09:00:00 GMT</pubDate>
      <category>AI Engineering</category>
      <description>Point it at a local model, a cloud model, or both. The value is choosing where your code goes.</description>
      <enclosure url="https://omarbadran.dev/img/blog/continue-dev-assistant.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>Getting Cited by AI Answer Engines</title>
      <link>https://omarbadran.dev/blog/llms-txt-geo</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/llms-txt-geo</guid>
      <pubDate>Wed, 03 Jun 2026 09:00:00 GMT</pubDate>
      <category>SEO</category>
      <description>People ask a model about you before they open a search engine. Generative engine optimisation is mostly just being unambiguous in machine-readable ways.</description>
      <enclosure url="https://omarbadran.dev/img/blog/llms-txt-geo.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>Model Context Protocol: Stop Writing Bespoke Tool Glue</title>
      <link>https://omarbadran.dev/blog/mcp-servers</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/mcp-servers</guid>
      <pubDate>Tue, 02 Jun 2026 09:00:00 GMT</pubDate>
      <category>AI Engineering</category>
      <description>One protocol so any assistant can talk to your database, your files, your ticketing system. Write the server once.</description>
      <enclosure url="https://omarbadran.dev/img/blog/mcp-servers.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>When the Best Checkout Is No Checkout</title>
      <link>https://omarbadran.dev/blog/whatsapp-checkout</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/whatsapp-checkout</guid>
      <pubDate>Tue, 26 May 2026 09:00:00 GMT</pubDate>
      <category>Product</category>
      <description>I built a storefront with no payment gateway on purpose. In the right market, a well-formed WhatsApp message converts better than any card form you can design.</description>
      <enclosure url="https://omarbadran.dev/img/blog/whatsapp-checkout.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>LangChain: When the Framework Helps and When It Hurts</title>
      <link>https://omarbadran.dev/blog/langchain-when-to-use</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/langchain-when-to-use</guid>
      <pubDate>Tue, 26 May 2026 09:00:00 GMT</pubDate>
      <category>AI Engineering</category>
      <description>For a three-step chain, the raw SDK is shorter and clearer. For an agent with twelve tools and retries, it is not.</description>
      <enclosure url="https://omarbadran.dev/img/blog/langchain-when-to-use.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>LlamaIndex: RAG Beyond the Toy Example</title>
      <link>https://omarbadran.dev/blog/llamaindex-rag</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/llamaindex-rag</guid>
      <pubDate>Tue, 19 May 2026 09:00:00 GMT</pubDate>
      <category>AI Engineering</category>
      <description>Chunking strategy decides whether your retrieval works. Everything else is a distant second.</description>
      <enclosure url="https://omarbadran.dev/img/blog/llamaindex-rag.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>Security by Design When You Are the Whole Team</title>
      <link>https://omarbadran.dev/blog/security-by-design-small-teams</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/security-by-design-small-teams</guid>
      <pubDate>Mon, 18 May 2026 09:00:00 GMT</pubDate>
      <category>Security</category>
      <description>You do not get a security review, a pentest budget, or a second pair of eyes. What you get is the ability to make the cheap decisions early — before they become expensive.</description>
      <enclosure url="https://omarbadran.dev/img/blog/security-by-design-small-teams.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>Qdrant: Picking a Vector Database Without the Hype</title>
      <link>https://omarbadran.dev/blog/qdrant-vector-search</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/qdrant-vector-search</guid>
      <pubDate>Tue, 12 May 2026 09:00:00 GMT</pubDate>
      <category>AI Engineering</category>
      <description>Filtered search is the feature that decides this, not raw benchmark numbers nobody reproduces.</description>
      <enclosure url="https://omarbadran.dev/img/blog/qdrant-vector-search.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>Never Put Your API Key in the Browser</title>
      <link>https://omarbadran.dev/blog/llm-proxy-pii</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/llm-proxy-pii</guid>
      <pubDate>Fri, 08 May 2026 09:00:00 GMT</pubDate>
      <category>Security</category>
      <description>Every AI feature I ship sits behind a server proxy that redacts personal data before it leaves the building. Here is the shape of that proxy, and why each part exists.</description>
      <enclosure url="https://omarbadran.dev/img/blog/llm-proxy-pii.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>n8n: Automation That Survives the Client Handover</title>
      <link>https://omarbadran.dev/blog/n8n-ai-automation</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/n8n-ai-automation</guid>
      <pubDate>Tue, 05 May 2026 09:00:00 GMT</pubDate>
      <category>AI Engineering</category>
      <description>A workflow the client can see and edit beats a cron job only you understand.</description>
      <enclosure url="https://omarbadran.dev/img/blog/n8n-ai-automation.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>Email OTP That Is Not Security Theatre</title>
      <link>https://omarbadran.dev/blog/email-otp-2fa</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/email-otp-2fa</guid>
      <pubDate>Tue, 28 Apr 2026 09:00:00 GMT</pubDate>
      <category>Security</category>
      <description>One-time codes are easy to add and easy to get wrong. Six digits with no rate limit, no expiry, and a leaky error message is worse than no second factor at all.</description>
      <enclosure url="https://omarbadran.dev/img/blog/email-otp-2fa.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>Dify: Giving Non-Developers a Safe AI Playground</title>
      <link>https://omarbadran.dev/blog/dify-llmops</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/dify-llmops</guid>
      <pubDate>Tue, 28 Apr 2026 09:00:00 GMT</pubDate>
      <category>AI Engineering</category>
      <description>Prompt versioning, logs, and spend limits — the boring parts that make an AI feature survive contact with a real team.</description>
      <enclosure url="https://omarbadran.dev/img/blog/dify-llmops.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>Ragas: You Cannot Improve a RAG You Do Not Measure</title>
      <link>https://omarbadran.dev/blog/ragas-eval</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/ragas-eval</guid>
      <pubDate>Tue, 21 Apr 2026 09:00:00 GMT</pubDate>
      <category>AI Engineering</category>
      <description>Faithfulness, relevance, context precision. Three numbers that turn &quot;it feels better&quot; into a decision.</description>
      <enclosure url="https://omarbadran.dev/img/blog/ragas-eval.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>Core Web Vitals on an Image-Heavy Site</title>
      <link>https://omarbadran.dev/blog/image-heavy-cwv</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/image-heavy-cwv</guid>
      <pubDate>Thu, 16 Apr 2026 09:00:00 GMT</pubDate>
      <category>Performance</category>
      <description>Photography studios, interior designers, florists — my clients sell with pictures. Making those sites fast is a constraint problem, not a plugin you install.</description>
      <enclosure url="https://omarbadran.dev/img/blog/image-heavy-cwv.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>Unsloth: Fine-Tuning on Hardware You Already Have</title>
      <link>https://omarbadran.dev/blog/unsloth-finetuning</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/unsloth-finetuning</guid>
      <pubDate>Tue, 14 Apr 2026 09:00:00 GMT</pubDate>
      <category>AI Engineering</category>
      <description>Before you fine-tune anything, read the part about why your problem is probably a retrieval problem.</description>
      <enclosure url="https://omarbadran.dev/img/blog/unsloth-finetuning.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>Agent Patterns That Survive Production</title>
      <link>https://omarbadran.dev/blog/openai-agents-patterns</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/openai-agents-patterns</guid>
      <pubDate>Tue, 07 Apr 2026 09:00:00 GMT</pubDate>
      <category>AI Engineering</category>
      <description>Loop limits, tool timeouts, and a hard budget. An agent without these is an outage with a personality.</description>
      <enclosure url="https://omarbadran.dev/img/blog/openai-agents-patterns.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>Self-Host Your Fonts. All of Them.</title>
      <link>https://omarbadran.dev/blog/self-host-fonts</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/self-host-fonts</guid>
      <pubDate>Sun, 05 Apr 2026 09:00:00 GMT</pubDate>
      <category>Performance</category>
      <description>Two link tags to a font CDN cost you a DNS lookup, a connection, a redirect chain, and a layout shift — on the most visible text on the page.</description>
      <enclosure url="https://omarbadran.dev/img/blog/self-host-fonts.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>The OWASP LLM Top 10, Translated Into Actual Fixes</title>
      <link>https://omarbadran.dev/blog/owasp-llm-top-10</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/owasp-llm-top-10</guid>
      <pubDate>Tue, 31 Mar 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <description>Prompt injection, insecure output handling, excessive agency. Each one with the line of code that prevents it.</description>
      <enclosure url="https://omarbadran.dev/img/blog/owasp-llm-top-10.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>One Monorepo Per Client</title>
      <link>https://omarbadran.dev/blog/client-monorepo</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/client-monorepo</guid>
      <pubDate>Tue, 24 Mar 2026 09:00:00 GMT</pubDate>
      <category>Engineering</category>
      <description>Public site, admin dashboard, API. Three apps that must agree on types and ship together. Splitting them across three repos is how small teams create integration bugs.</description>
      <enclosure url="https://omarbadran.dev/img/blog/client-monorepo.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>Prompt Injection Is Not a Prompt Problem</title>
      <link>https://omarbadran.dev/blog/prompt-injection-defense</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/prompt-injection-defense</guid>
      <pubDate>Tue, 24 Mar 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <description>You cannot instruct your way out of it. The fix is architectural: assume the model will be turned against you.</description>
      <enclosure url="https://omarbadran.dev/img/blog/prompt-injection-defense.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>Garak: Scan Your LLM App Before Someone Else Does</title>
      <link>https://omarbadran.dev/blog/garak-llm-scanner</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/garak-llm-scanner</guid>
      <pubDate>Tue, 17 Mar 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <description>A vulnerability scanner aimed at model behaviour — jailbreaks, leakage, toxicity — run in CI like any other test.</description>
      <enclosure url="https://omarbadran.dev/img/blog/garak-llm-scanner.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>Write Case Studies, Not Screenshots</title>
      <link>https://omarbadran.dev/blog/case-studies-not-screenshots</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/case-studies-not-screenshots</guid>
      <pubDate>Wed, 11 Mar 2026 09:00:00 GMT</pubDate>
      <category>Career</category>
      <description>The five-part structure I use for every project write-up, and the one question that decides whether a paragraph stays in or gets cut.</description>
      <enclosure url="https://omarbadran.dev/img/blog/case-studies-not-screenshots.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>Red-Teaming Your Own AI Feature</title>
      <link>https://omarbadran.dev/blog/pyrit-red-teaming</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/pyrit-red-teaming</guid>
      <pubDate>Tue, 10 Mar 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <description>An hour of structured attack attempts before launch is worth more than any amount of post-incident analysis.</description>
      <enclosure url="https://omarbadran.dev/img/blog/pyrit-red-teaming.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>Presidio: Redaction That Beats Your Regex</title>
      <link>https://omarbadran.dev/blog/presidio-pii-redaction</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/presidio-pii-redaction</guid>
      <pubDate>Tue, 03 Mar 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <description>My hand-rolled patterns caught emails and phones. They missed everything shaped slightly differently.</description>
      <enclosure url="https://omarbadran.dev/img/blog/presidio-pii-redaction.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>Treat Model Output Like User Input</title>
      <link>https://omarbadran.dev/blog/llm-guard-output</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/llm-guard-output</guid>
      <pubDate>Tue, 24 Feb 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <description>Rendering generated text as HTML is XSS where the payload is written by a stranger through your own feature.</description>
      <enclosure url="https://omarbadran.dev/img/blog/llm-guard-output.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>That Model File Is Executable Code</title>
      <link>https://omarbadran.dev/blog/model-supply-chain</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/model-supply-chain</guid>
      <pubDate>Tue, 17 Feb 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <description>Pickle-based checkpoints can run arbitrary code on load. Downloading weights from a random mirror is not neutral.</description>
      <enclosure url="https://omarbadran.dev/img/blog/model-supply-chain.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>The Blast Radius of an Autonomous Agent</title>
      <link>https://omarbadran.dev/blog/agentic-ai-risk</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/agentic-ai-risk</guid>
      <pubDate>Tue, 10 Feb 2026 09:00:00 GMT</pubDate>
      <category>AI Security</category>
      <description>Give an agent shell access and a budget, and you have built an insider threat that never sleeps.</description>
      <enclosure url="https://omarbadran.dev/img/blog/agentic-ai-risk.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>Nuclei: Vulnerability Scanning You Can Read</title>
      <link>https://omarbadran.dev/blog/nuclei-templates</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/nuclei-templates</guid>
      <pubDate>Tue, 03 Feb 2026 09:00:00 GMT</pubDate>
      <category>Security</category>
      <description>Templates are YAML. You can audit exactly what a check does before you run it against a client.</description>
      <enclosure url="https://omarbadran.dev/img/blog/nuclei-templates.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>Writing a Semgrep Rule for Your Own Codebase</title>
      <link>https://omarbadran.dev/blog/semgrep-custom-rules</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/semgrep-custom-rules</guid>
      <pubDate>Tue, 27 Jan 2026 09:00:00 GMT</pubDate>
      <category>Security</category>
      <description>The generic ruleset finds generic bugs. The rule you write for your own mistake finds it forever.</description>
      <enclosure url="https://omarbadran.dev/img/blog/semgrep-custom-rules.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>Trivy: One Scanner for Images, IaC and Dependencies</title>
      <link>https://omarbadran.dev/blog/trivy-container-scanning</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/trivy-container-scanning</guid>
      <pubDate>Tue, 20 Jan 2026 09:00:00 GMT</pubDate>
      <category>Security</category>
      <description>Add it to CI in ten minutes. Then spend a week deciding which findings you are actually going to fix.</description>
      <enclosure url="https://omarbadran.dev/img/blog/trivy-container-scanning.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>Your Dependency Tree Is Your Attack Surface</title>
      <link>https://omarbadran.dev/blog/osv-scanner-deps</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/osv-scanner-deps</guid>
      <pubDate>Tue, 13 Jan 2026 09:00:00 GMT</pubDate>
      <category>Security</category>
      <description>A twelve-line utility can pull in ninety packages. Every one of them runs with your privileges.</description>
      <enclosure url="https://omarbadran.dev/img/blog/osv-scanner-deps.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>The Secret You Committed Is Still in the History</title>
      <link>https://omarbadran.dev/blog/gitleaks-secret-scanning</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/gitleaks-secret-scanning</guid>
      <pubDate>Tue, 06 Jan 2026 09:00:00 GMT</pubDate>
      <category>Security</category>
      <description>Deleting the line does nothing. Rotating the credential is the only fix, and a pre-commit hook is the only prevention.</description>
      <enclosure url="https://omarbadran.dev/img/blog/gitleaks-secret-scanning.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>Secret Scanning That Verifies Before It Alarms</title>
      <link>https://omarbadran.dev/blog/trufflehog-verified-secrets</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/trufflehog-verified-secrets</guid>
      <pubDate>Tue, 30 Dec 2025 09:00:00 GMT</pubDate>
      <category>Security</category>
      <description>A scanner that tests whether a found key is live turns a thousand false positives into three real emergencies.</description>
      <enclosure url="https://omarbadran.dev/img/blog/trufflehog-verified-secrets.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>OWASP ZAP in CI Without Wrecking Your Pipeline</title>
      <link>https://omarbadran.dev/blog/zap-dast-ci</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/zap-dast-ci</guid>
      <pubDate>Tue, 23 Dec 2025 09:00:00 GMT</pubDate>
      <category>Security</category>
      <description>A baseline scan on every pull request, a full scan nightly. Getting that split wrong is why teams turn DAST off.</description>
      <enclosure url="https://omarbadran.dev/img/blog/zap-dast-ci.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>A SIEM for Teams Who Cannot Afford a SOC</title>
      <link>https://omarbadran.dev/blog/wazuh-siem-small</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/wazuh-siem-small</guid>
      <pubDate>Tue, 16 Dec 2025 09:00:00 GMT</pubDate>
      <category>Security</category>
      <description>Log collection you never read is theatre. Three alerts you actually respond to is a security programme.</description>
      <enclosure url="https://omarbadran.dev/img/blog/wazuh-siem-small.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>Detection as Code with Sigma Rules</title>
      <link>https://omarbadran.dev/blog/sigma-detection-rules</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/sigma-detection-rules</guid>
      <pubDate>Tue, 09 Dec 2025 09:00:00 GMT</pubDate>
      <category>Security</category>
      <description>Write the detection once in a vendor-neutral format, convert it to whatever your SIEM speaks.</description>
      <enclosure url="https://omarbadran.dev/img/blog/sigma-detection-rules.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>Testing Whether Your Alerts Actually Fire</title>
      <link>https://omarbadran.dev/blog/atomic-red-team</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/atomic-red-team</guid>
      <pubDate>Tue, 02 Dec 2025 09:00:00 GMT</pubDate>
      <category>Security</category>
      <description>Everyone deploys detection. Almost nobody verifies it triggers. Small, safe, mapped test cases fix that.</description>
      <enclosure url="https://omarbadran.dev/img/blog/atomic-red-team.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>Runtime Security: Catching What the Scanner Missed</title>
      <link>https://omarbadran.dev/blog/falco-runtime-security</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/falco-runtime-security</guid>
      <pubDate>Tue, 25 Nov 2025 09:00:00 GMT</pubDate>
      <category>Security</category>
      <description>A clean image can still spawn a shell at 3am. Build-time scanning cannot see that; runtime rules can.</description>
      <enclosure url="https://omarbadran.dev/img/blog/falco-runtime-security.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>Building a Recon Workflow With ProjectDiscovery Tools</title>
      <link>https://omarbadran.dev/blog/projectdiscovery-recon</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/projectdiscovery-recon</guid>
      <pubDate>Tue, 18 Nov 2025 09:00:00 GMT</pubDate>
      <category>Security</category>
      <description>Subfinder into httpx into nuclei. Three tools, one pipe, and the whole external surface of an authorised target.</description>
      <enclosure url="https://omarbadran.dev/img/blog/projectdiscovery-recon.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>Signing Your Artifacts Without Managing Keys</title>
      <link>https://omarbadran.dev/blog/sigstore-signing</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/sigstore-signing</guid>
      <pubDate>Tue, 11 Nov 2025 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <description>Keyless signing tied to your CI identity. The barrier to supply-chain integrity dropped to almost nothing.</description>
      <enclosure url="https://omarbadran.dev/img/blog/sigstore-signing.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>An SBOM Is Just an Honest Inventory</title>
      <link>https://omarbadran.dev/blog/sbom-syft-grype</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/sbom-syft-grype</guid>
      <pubDate>Tue, 04 Nov 2025 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <description>When the next Log4j lands, the only question that matters is &quot;are we affected&quot;. An SBOM answers it in seconds.</description>
      <enclosure url="https://omarbadran.dev/img/blog/sbom-syft-grype.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>Automating Dependency Updates Without Drowning</title>
      <link>https://omarbadran.dev/blog/renovate-dependency-updates</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/renovate-dependency-updates</guid>
      <pubDate>Tue, 28 Oct 2025 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <description>Grouping, scheduling and auto-merge for patches. Otherwise you get forty pull requests and ignore all of them.</description>
      <enclosure url="https://omarbadran.dev/img/blog/renovate-dependency-updates.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>Your CI Has More Secrets Than Your Production Server</title>
      <link>https://omarbadran.dev/blog/github-actions-hardening</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/github-actions-hardening</guid>
      <pubDate>Tue, 21 Oct 2025 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <description>Pin actions to a commit SHA, scope permissions per job, never run untrusted code on a privileged trigger.</description>
      <enclosure url="https://omarbadran.dev/img/blog/github-actions-hardening.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>Where Client Project Secrets Should Actually Live</title>
      <link>https://omarbadran.dev/blog/infisical-secrets</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/infisical-secrets</guid>
      <pubDate>Tue, 14 Oct 2025 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <description>Not in the repo, not in a WhatsApp message, not in a .env you emailed. Here is the small-team answer.</description>
      <enclosure url="https://omarbadran.dev/img/blog/infisical-secrets.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>The Pre-Commit Hooks Worth Installing Today</title>
      <link>https://omarbadran.dev/blog/pre-commit-hooks</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/pre-commit-hooks</guid>
      <pubDate>Tue, 07 Oct 2025 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <description>Secret scan, formatter, linter, large-file guard. Four hooks that prevent the four most common self-inflicted wounds.</description>
      <enclosure url="https://omarbadran.dev/img/blog/pre-commit-hooks.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>A Smaller Image Is a Smaller Attack Surface</title>
      <link>https://omarbadran.dev/blog/docker-image-slimming</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/docker-image-slimming</guid>
      <pubDate>Tue, 30 Sep 2025 09:00:00 GMT</pubDate>
      <category>DevSecOps</category>
      <description>No shell, no package manager, no curl. Most of your CVE count comes from tools your app never uses.</description>
      <enclosure url="https://omarbadran.dev/img/blog/docker-image-slimming.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>Biome: Replacing Two Tools With One Fast One</title>
      <link>https://omarbadran.dev/blog/biome-toolchain</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/biome-toolchain</guid>
      <pubDate>Tue, 23 Sep 2025 09:00:00 GMT</pubDate>
      <category>Tooling</category>
      <description>Linting and formatting in a single binary. On a mid-size project the difference is seconds versus instant.</description>
      <enclosure url="https://omarbadran.dev/img/blog/biome-toolchain.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>Bun: Where It Wins and Where I Still Use Node</title>
      <link>https://omarbadran.dev/blog/bun-runtime</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/bun-runtime</guid>
      <pubDate>Tue, 16 Sep 2025 09:00:00 GMT</pubDate>
      <category>Tooling</category>
      <description>Install speed and the test runner are genuinely great. Production deployment is where I stay conservative.</description>
      <enclosure url="https://omarbadran.dev/img/blog/bun-runtime.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>Astro: Ship Less JavaScript on Content Sites</title>
      <link>https://omarbadran.dev/blog/astro-islands</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/astro-islands</guid>
      <pubDate>Tue, 09 Sep 2025 09:00:00 GMT</pubDate>
      <category>Tooling</category>
      <description>A marketing site does not need a hydrated framework on every page. Islands make that an architecture, not a compromise.</description>
      <enclosure url="https://omarbadran.dev/img/blog/astro-islands.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>The Copy-Paste Component Model</title>
      <link>https://omarbadran.dev/blog/shadcn-copy-paste-ui</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/shadcn-copy-paste-ui</guid>
      <pubDate>Tue, 02 Sep 2025 09:00:00 GMT</pubDate>
      <category>Tooling</category>
      <description>You own the file, so you can restyle it into a brutalist theme without fighting a library you cannot edit.</description>
      <enclosure url="https://omarbadran.dev/img/blog/shadcn-copy-paste-ui.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>Playwright: The Only Tests Clients Ever Notice</title>
      <link>https://omarbadran.dev/blog/playwright-e2e</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/playwright-e2e</guid>
      <pubDate>Tue, 26 Aug 2025 09:00:00 GMT</pubDate>
      <category>Tooling</category>
      <description>Unit tests protect you. End-to-end tests protect the checkout. Guess which one the client cares about.</description>
      <enclosure url="https://omarbadran.dev/img/blog/playwright-e2e.webp" type="image/webp" length="0"/>
    </item>
    <item>
      <title>TypeScript Types Vanish at Runtime</title>
      <link>https://omarbadran.dev/blog/zod-runtime-validation</link>
      <guid isPermaLink="true">https://omarbadran.dev/blog/zod-runtime-validation</guid>
      <pubDate>Tue, 19 Aug 2025 09:00:00 GMT</pubDate>
      <category>Tooling</category>
      <description>Your compile-time safety does nothing to a malformed request body. One schema per route closes the gap.</description>
      <enclosure url="https://omarbadran.dev/img/blog/zod-runtime-validation.webp" type="image/webp" length="0"/>
    </item>
  </channel>
</rss>
