<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Maciej Stepkowski</title><description>Engineering write-ups on building kubemend, an LLM agent harness for Kubernetes remediation, and other systems work.</description><link>https://stepkowski.dev/</link><item><title>Prompt-injecting my own SRE agent through its logs — and finding the attack landed somewhere I hadn&apos;t designed for</title><link>https://stepkowski.dev/blog/prompt-injection-scenario/</link><guid isPermaLink="true">https://stepkowski.dev/blog/prompt-injection-scenario/</guid><description>A planted &apos;ignore previous instructions&apos; payload reached the model through a tool I hadn&apos;t built the scenario around — and why the system prompt&apos;s blanket stance mattered more than the specific attack surface I designed for.</description><pubDate>Sun, 16 Aug 2026 00:00:00 GMT</pubDate></item><item><title>I accidentally ran two copies of my own verification harness against the same cluster — here&apos;s how I found out, and what it cost</title><link>https://stepkowski.dev/blog/concurrency-incident/</link><guid isPermaLink="true">https://stepkowski.dev/blog/concurrency-incident/</guid><description>Two copies of the same eval harness ran against one cluster for twenty minutes without either knowing about the other. How the traces caught it, and how to recover data instead of discarding all of it.</description><pubDate>Sat, 15 Aug 2026 00:00:00 GMT</pubDate></item><item><title>I built a Kubernetes remediation agent that can only open pull requests — here&apos;s what the eval runs cost and taught me</title><link>https://stepkowski.dev/blog/verification-pipeline-cost/</link><guid isPermaLink="true">https://stepkowski.dev/blog/verification-pipeline-cost/</guid><description>kubemend verifies every proposed fix independently instead of trusting the model — and that verification pipeline had its own bugs. Two of them, and what a 30-run eval sweep against a real cluster cost to find.</description><pubDate>Fri, 14 Aug 2026 00:00:00 GMT</pubDate></item></channel></rss>