<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:news="http://www.google.com/schemas/sitemap-news/0.9">
  <url>
    <loc>https://hackyjs.com/posts/cost-per-useful-agent-task-why-cached-tokens-break-naive-inference-pricing-math</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-23T00:00:00.000Z</news:publication_date>
      <news:title>Cost per Useful Agent Task: Why Cached Tokens Break Naive Inference Pricing Math</news:title>
      <news:keywords>prompt-caching, inference-cost, llm-agents, cost-optimization</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/how-ghappier-turned-npm-trusted-publishing-into-a-package-poisoning-pipeline</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-23T00:00:00.000Z</news:publication_date>
      <news:title>How GHAPPIER Turned npm Trusted Publishing Into a Package Poisoning Pipeline</news:title>
      <news:keywords>supply-chain, npm, github-actions, ci-cd, malware</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/verifying-changesets-v3s-88-install-size-claim-in-a-real-ci-pipeline</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-23T00:00:00.000Z</news:publication_date>
      <news:title>Verifying Changesets v3&apos;s 88% Install-Size Claim in a Real CI Pipeline</news:title>
      <news:keywords>changesets, esm, monorepo, npm, ci-cd</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/what-breaks-when-you-port-fastapi-to-pyodide-on-cloudflare-workers</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-23T00:00:00.000Z</news:publication_date>
      <news:title>What Breaks When You Port FastAPI to Pyodide on Cloudflare Workers</news:title>
      <news:keywords>fastapi, pyodide, cloudflare-workers, python, serverless</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/anatomy-of-the-meta-muse-0-day-how-prompt-injection-becomes-a-hijacked-tool-call</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-22T00:00:00.000Z</news:publication_date>
      <news:title>Anatomy of the Meta Muse 0-Day: How Prompt Injection Becomes a Hijacked Tool Call</news:title>
      <news:keywords>ai-agents, security, prompt-injection, tool-calling, meta-muse</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/auditing-ai-agent-tool-execution-on-macos-after-the-meta-muse-zero-day</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-22T00:00:00.000Z</news:publication_date>
      <news:title>Auditing AI Agent Tool Execution on macOS After the Meta Muse Zero-Day</news:title>
      <news:keywords>ai-agent-security, macos, zero-day, sandboxing, malware-injection</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/auditing-heif-decoding-in-server-side-javascript-after-the-heif-heist</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-22T00:00:00.000Z</news:publication_date>
      <news:title>Auditing HEIF Decoding in Server-Side JavaScript After the HEIF Heist</news:title>
      <news:keywords>heif, image-parsing, rce, nodejs, security</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/building-a-cost-per-task-ledger-for-agent-pipelines-on-gpt-6-opus-55-and-grok-47</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-22T00:00:00.000Z</news:publication_date>
      <news:title>Building a Cost-Per-Task Ledger for Agent Pipelines on GPT-6, Opus 5.5, and Grok 4.7</news:title>
      <news:keywords>llm-costs, agent-pipelines, inference-economics, prompt-caching, api-pricing</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/lifecycle-script-diffing-and-provenance-checks-hardening-npm-releases-after-the-65-repo-breach</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-22T00:00:00.000Z</news:publication_date>
      <news:title>Lifecycle-Script Diffing and Provenance Checks: Hardening npm Releases After the 65-Repo Breach</news:title>
      <news:keywords>npm, supply-chain-security, ci-cd, provenance, github-actions</news:keywords>
    </news:news>
  </url>
  <url>
    <loc>https://hackyjs.com/posts/porting-a-real-python-backend-to-cloudflare-workers-what-pyodidewasm-actually-breaks</loc>
    <news:news>
      <news:publication>
        <news:name>Hacky JS</news:name>
        <news:language>en</news:language>
      </news:publication>
      <news:publication_date>2026-09-22T00:00:00.000Z</news:publication_date>
      <news:title>Porting a Real Python Backend to Cloudflare Workers: What Pyodide/WASM Actually Breaks</news:title>
      <news:keywords>cloudflare-workers, python, pyodide, wasm, edge-computing</news:keywords>
    </news:news>
  </url>
</urlset>
