<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
  <channel>
    <title>fibon design log (English)</title>
    <link>https://fibon.stepbyday.com/en/</link>
    <description>fibon — the design log of an auditable white-box personal-assistant agent project</description>
    <language>en</language>
    <item>
      <title>Chapter 1: Why I'm Building My Own AI Assistant</title>
      <link>https://fibon.stepbyday.com/en/chapters/01-fibonacci/</link>
      <guid>https://fibon.stepbyday.com/en/chapters/01-fibonacci/</guid>
      <description>A seed planted the moment ChatGPT exploded — and why I didn't start building until 2026</description>
      <pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Chapter 2: Is One AI Not Enough?</title>
      <link>https://fibon.stepbyday.com/en/chapters/02-butler-and-assistants/</link>
      <guid>https://fibon.stepbyday.com/en/chapters/02-butler-and-assistants/</guid>
      <description>Why fibon splits the Butler from the Assistants, and why the rules of delegation must be hard-coded instead of merely &quot;asking&quot; the AI nicely</description>
      <pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Field Note: Zombie Caches and Stolen Keys: A Teardown of Two Runaway AI Bills</title>
      <link>https://fibon.stepbyday.com/en/notes/2026-06-gemini-cache-billing/</link>
      <guid>https://fibon.stepbyday.com/en/notes/2026-06-gemini-cache-billing/</guid>
      <description>Reverse-engineering how Google's billing system broke from the shape of a BigQuery export — and an honest audit of which defenses fibon has built, and which one is still missing</description>
      <pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Field Note: Runaway Sub-Agents: The June 2 Claude Outage and the Lesson of the Infinite Loop</title>
      <link>https://fibon.stepbyday.com/en/notes/2026-06-claude-outage/</link>
      <guid>https://fibon.stepbyday.com/en/notes/2026-06-claude-outage/</guid>
      <description>A bug that made sub-agents multiply exponentially knocked Claude out for nearly six hours. fibon's delegation-round cap and multi-vendor design are built for exactly this kind of runaway — but one piece I haven't built either.</description>
      <pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Field Note: The Attack That Waits: When AI's 'Memory' Becomes the Attack Surface</title>
      <link>https://fibon.stepbyday.com/en/notes/2026-06-memory-poisoning/</link>
      <guid>https://fibon.stepbyday.com/en/notes/2026-06-memory-poisoning/</guid>
      <description>OWASP put memory poisoning in its 2026 agentic top ten; a single poisoned webpage can make an agent misfire weeks later. fibon sells memory as a core feature — this cut lands right on the vital spot.</description>
      <pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Field Note: The Lobster's Bill: When an AI Agent's 'Token-Eating Monster' Meets the Abandonment Wave</title>
      <link>https://fibon.stepbyday.com/en/notes/2026-06-openclaw-token-economics/</link>
      <guid>https://fibon.stepbyday.com/en/notes/2026-06-openclaw-token-economics/</guid>
      <description>OpenClaw drove the whole world to &quot;raise a lobster&quot; — then the same crowd abandoned it because $150/day in token fees made it unaffordable. The economics of that craze is exactly fibon's core thesis.</description>
      <pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Field Note: 12% of the Marketplace Was Poison: The ClawHub Supply-Chain Attack</title>
      <link>https://fibon.stepbyday.com/en/notes/2026-06-clawhub-supply-chain/</link>
      <guid>https://fibon.stepbyday.com/en/notes/2026-06-clawhub-supply-chain/</guid>
      <description>OpenClaw's skill marketplace was seeded with over a thousand malicious add-ons — using no 0-day at all. A teardown, and a test of whether fibon's three-gate skill import actually holds.</description>
      <pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate>
    </item>
    <item>
      <title>Field Note: Tools as Attack Surface: 2026's MCP Vulnerability Cascade and 'Tool Poisoning'</title>
      <link>https://fibon.stepbyday.com/en/notes/2026-06-mcp-vulnerabilities/</link>
      <guid>https://fibon.stepbyday.com/en/notes/2026-06-mcp-vulnerabilities/</guid>
      <description>From three CVEs in Anthropic's own Git MCP to a STDIO design flaw that exposed 7,000 servers — MCP turned &quot;connecting external tools&quot; into a new supply-chain battlefield. How much can fibon's trust tiering and tool-hash verification stop?</description>
      <pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate>
    </item>
  </channel>
</rss>