<?xml version="1.0" encoding="utf-8" standalone="yes"?><urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9" xmlns:xhtml="http://www.w3.org/1999/xhtml"><url><loc>https://oddguan.com/tags/add-skill/</loc><lastmod>2026-03-08T00:00:00+00:00</lastmod><changefreq>weekly</changefreq><priority>0.5</priority></url><url><loc>https://oddguan.com/blog/agent-skillslip-google-gemini-cli-anthropic-claude-code-vercel-add-skill-path-traversal/</loc><lastmod>2026-03-08T00:00:00+00:00</lastmod><changefreq>weekly</changefreq><priority>0.5</priority></url><url><loc>https://oddguan.com/tags/ai-security/</loc><lastmod>2026-03-08T00:00:00+00:00</lastmod><changefreq>weekly</changefreq><priority>0.5</priority></url><url><loc>https://oddguan.com/</loc><lastmod>2026-03-08T00:00:00+00:00</lastmod><changefreq>weekly</changefreq><priority>0.5</priority></url><url><loc>https://oddguan.com/blog/</loc><lastmod>2026-03-08T00:00:00+00:00</lastmod><changefreq>weekly</changefreq><priority>0.5</priority></url><url><loc>https://oddguan.com/tags/claude-code/</loc><lastmod>2026-03-08T00:00:00+00:00</lastmod><changefreq>weekly</changefreq><priority>0.5</priority></url><url><loc>https://oddguan.com/tags/gemini-cli/</loc><lastmod>2026-03-08T00:00:00+00:00</lastmod><changefreq>weekly</changefreq><priority>0.5</priority></url><url><loc>https://oddguan.com/tags/path-traversal/</loc><lastmod>2026-03-08T00:00:00+00:00</lastmod><changefreq>weekly</changefreq><priority>0.5</priority></url><url><loc>https://oddguan.com/tags/skillslip/</loc><lastmod>2026-03-08T00:00:00+00:00</lastmod><changefreq>weekly</changefreq><priority>0.5</priority></url><url><loc>https://oddguan.com/tags/supply-chain/</loc><lastmod>2026-03-08T00:00:00+00:00</lastmod><changefreq>weekly</changefreq><priority>0.5</priority></url><url><loc>https://oddguan.com/tags/symlink/</loc><lastmod>2026-03-08T00:00:00+00:00</lastmod><changefreq>weekly</changefreq><priority>0.5</priority></url><url><loc>https://oddguan.com/tags/</loc><lastmod>2026-03-08T00:00:00+00:00</lastmod><changefreq>weekly</changefreq><priority>0.5</priority></url><url><loc>https://oddguan.com/tags/capability-laundering/</loc><lastmod>2026-02-28T00:00:00+00:00</lastmod><changefreq>weekly</changefreq><priority>0.5</priority></url><url><loc>https://oddguan.com/blog/anthropic-mcp-server-git-add-path-traversal-credential-exfiltration-capability-laundering-cve-2026-27735/</loc><lastmod>2026-02-28T00:00:00+00:00</lastmod><changefreq>weekly</changefreq><priority>0.5</priority></url><url><loc>https://oddguan.com/tags/credential-theft/</loc><lastmod>2026-02-28T00:00:00+00:00</lastmod><changefreq>weekly</changefreq><priority>0.5</priority></url><url><loc>https://oddguan.com/tags/cve-2026-27735/</loc><lastmod>2026-02-28T00:00:00+00:00</lastmod><changefreq>weekly</changefreq><priority>0.5</priority></url><url><loc>https://oddguan.com/tags/git/</loc><lastmod>2026-02-28T00:00:00+00:00</lastmod><changefreq>weekly</changefreq><priority>0.5</priority></url><url><loc>https://oddguan.com/tags/gitpython/</loc><lastmod>2026-02-28T00:00:00+00:00</lastmod><changefreq>weekly</changefreq><priority>0.5</priority></url><url><loc>https://oddguan.com/tags/mcp/</loc><lastmod>2026-02-28T00:00:00+00:00</lastmod><changefreq>weekly</changefreq><priority>0.5</priority></url><url><loc>https://oddguan.com/tags/fflate/</loc><lastmod>2026-01-17T00:00:00+00:00</lastmod><changefreq>weekly</changefreq><priority>0.5</priority></url><url><loc>https://oddguan.com/tags/file-overwrite/</loc><lastmod>2026-01-17T00:00:00+00:00</lastmod><changefreq>weekly</changefreq><priority>0.5</priority></url><url><loc>https://oddguan.com/blog/mcp-bundle-security-zip-slip-overwrite-for-mcp-client/</loc><lastmod>2026-01-17T00:00:00+00:00</lastmod><changefreq>weekly</changefreq><priority>0.5</priority></url><url><loc>https://oddguan.com/tags/mcpb/</loc><lastmod>2026-01-17T00:00:00+00:00</lastmod><changefreq>weekly</changefreq><priority>0.5</priority></url><url><loc>https://oddguan.com/tags/zip-slip/</loc><lastmod>2026-01-17T00:00:00+00:00</lastmod><changefreq>weekly</changefreq><priority>0.5</priority></url><url><loc>https://oddguan.com/blog/anthropic-mcp-server-git-credential-exfiltration-capability-laundering-cve-2025-68143/</loc><lastmod>2025-12-28T00:00:00+00:00</lastmod><changefreq>weekly</changefreq><priority>0.5</priority></url><url><loc>https://oddguan.com/tags/anthropic/</loc><lastmod>2025-12-27T00:00:00+00:00</lastmod><changefreq>weekly</changefreq><priority>0.5</priority></url><url><loc>https://oddguan.com/blog/anthropic-memory-mcp-server-terminal-hijacking-capability-laundering/</loc><lastmod>2025-12-27T00:00:00+00:00</lastmod><changefreq>weekly</changefreq><priority>0.5</priority></url><url><loc>https://oddguan.com/tags/configuration-injection/</loc><lastmod>2025-12-27T00:00:00+00:00</lastmod><changefreq>weekly</changefreq><priority>0.5</priority></url><url><loc>https://oddguan.com/tags/vs-code/</loc><lastmod>2025-12-27T00:00:00+00:00</lastmod><changefreq>weekly</changefreq><priority>0.5</priority></url><url><loc>https://oddguan.com/tags/cve/</loc><lastmod>2025-12-03T00:00:00+00:00</lastmod><changefreq>weekly</changefreq><priority>0.5</priority></url><url><loc>https://oddguan.com/blog/anthropic-sandbox-cve-2025-66479/</loc><lastmod>2025-12-03T00:00:00+00:00</lastmod><changefreq>weekly</changefreq><priority>0.5</priority></url><url><loc>https://oddguan.com/tags/sandbox/</loc><lastmod>2025-12-03T00:00:00+00:00</lastmod><changefreq>weekly</changefreq><priority>0.5</priority></url><url><loc>https://oddguan.com/talks/</loc><lastmod>2025-11-01T00:00:00+00:00</lastmod><changefreq>weekly</changefreq><priority>0.5</priority></url><url><loc>https://oddguan.com/categories/ai-security/</loc><lastmod>2025-09-25T00:00:00+00:00</lastmod><changefreq>weekly</changefreq><priority>0.5</priority></url><url><loc>https://oddguan.com/categories/</loc><lastmod>2025-09-25T00:00:00+00:00</lastmod><changefreq>weekly</changefreq><priority>0.5</priority></url><url><loc>https://oddguan.com/blog/microsoft-omniparser-gui-agent-computer-use-rce-cve-2025-55322/</loc><lastmod>2025-09-25T00:00:00+00:00</lastmod><changefreq>weekly</changefreq><priority>0.5</priority></url><url><loc>https://oddguan.com/tags/computer-use/</loc><lastmod>2025-09-25T00:00:00+00:00</lastmod><changefreq>weekly</changefreq><priority>0.5</priority></url><url><loc>https://oddguan.com/tags/cve-2025-55322/</loc><lastmod>2025-09-25T00:00:00+00:00</lastmod><changefreq>weekly</changefreq><priority>0.5</priority></url><url><loc>https://oddguan.com/tags/microsoft-omniparser/</loc><lastmod>2025-09-25T00:00:00+00:00</lastmod><changefreq>weekly</changefreq><priority>0.5</priority></url><url><loc>https://oddguan.com/tags/rce/</loc><lastmod>2025-09-25T00:00:00+00:00</lastmod><changefreq>weekly</changefreq><priority>0.5</priority></url><url><loc>https://oddguan.com/categories/vulnerability-research/</loc><lastmod>2025-09-25T00:00:00+00:00</lastmod><changefreq>weekly</changefreq><priority>0.5</priority></url><url><loc>https://oddguan.com/tags/microsoft/</loc><lastmod>2025-08-06T00:00:00+00:00</lastmod><changefreq>weekly</changefreq><priority>0.5</priority></url><url><loc>https://oddguan.com/tags/nlweb/</loc><lastmod>2025-08-06T00:00:00+00:00</lastmod><changefreq>weekly</changefreq><priority>0.5</priority></url><url><loc>https://oddguan.com/blog/nlweb-path-traversal/</loc><lastmod>2025-08-06T00:00:00+00:00</lastmod><changefreq>weekly</changefreq><priority>0.5</priority></url><url><loc>https://oddguan.com/cv/</loc><lastmod>2024-01-01T00:00:00+00:00</lastmod><changefreq>weekly</changefreq><priority>0.5</priority></url><url><loc>https://oddguan.com/vulnerabilities/</loc><lastmod>2024-01-01T00:00:00+00:00</lastmod><changefreq>weekly</changefreq><priority>0.5</priority></url></urlset>