<?xml version="1.0" encoding="UTF-8"?>
<urlset xmlns="http://www.sitemaps.org/schemas/sitemap/0.9">
  <url>
    <loc>https://www.canyonroad.ai/</loc>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/how-it-works/</loc>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/use-cases/</loc>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/execution-layer-security/</loc>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/faq/</loc>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/contact/</loc>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/products/agentsh/</loc>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/products/beacon/</loc>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/products/watchtower/</loc>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/blog/the-control-gap-agents-move-faster-than-humans-can-supervise/</loc>
    <lastmod>2026-02-14T00:00:00.000Z</lastmod>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/blog/intent-execution-audit-a-model-for-agent-control/</loc>
    <lastmod>2026-02-18T00:00:00.000Z</lastmod>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/blog/the-most-surprising-trait-of-AI-coding-agents/</loc>
    <lastmod>2026-02-19T00:00:00.000Z</lastmod>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/blog/when-an-ai-agent-complies/</loc>
    <lastmod>2026-02-27T00:00:00.000Z</lastmod>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/blog/breaking-the-agentic-kill-chain/</loc>
    <lastmod>2026-03-03T00:00:00.000Z</lastmod>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/blog/bugs-happen-agents-still-run/</loc>
    <lastmod>2026-03-05T00:00:00.000Z</lastmod>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/blog/one-line-under-the-agent/</loc>
    <lastmod>2026-03-09T00:00:00.000Z</lastmod>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/blog/the-worm-that-came-for-mcp/</loc>
    <lastmod>2026-03-12T00:00:00.000Z</lastmod>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/blog/rule-files-are-not-enforcement/</loc>
    <lastmod>2026-03-17T00:00:00.000Z</lastmod>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/blog/a-year-of-ai-tool-exploits-one-root-cause/</loc>
    <lastmod>2026-03-23T00:00:00.000Z</lastmod>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/blog/supply-chain-attacks-runtime-control/</loc>
    <lastmod>2026-03-26T00:00:00.000Z</lastmod>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/blog/command-injection-inherited-authority/</loc>
    <lastmod>2026-03-30T00:00:00.000Z</lastmod>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/blog/untrusted-text-trusted-shell/</loc>
    <lastmod>2026-04-02T00:00:00.000Z</lastmod>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/blog/author/eran-sandler/</loc>
    <lastmod>2026-04-03T17:50:14.756Z</lastmod>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/blog/author/gur-brosh/</loc>
    <lastmod>2026-04-03T17:50:14.756Z</lastmod>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/blog/</loc>
    <lastmod>2026-04-03T17:50:14.768Z</lastmod>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/blog/tag/agentic-ai/</loc>
    <lastmod>2026-04-03T17:50:14.772Z</lastmod>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/blog/tag/ai-security/</loc>
    <lastmod>2026-04-03T17:50:14.772Z</lastmod>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/blog/tag/governance/</loc>
    <lastmod>2026-04-03T17:50:14.772Z</lastmod>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/blog/tag/prompt-injection/</loc>
    <lastmod>2026-04-03T17:50:14.772Z</lastmod>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/blog/tag/developer-tools/</loc>
    <lastmod>2026-04-03T17:50:14.772Z</lastmod>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/blog/tag/runtime-security/</loc>
    <lastmod>2026-04-03T17:50:14.772Z</lastmod>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/blog/tag/llm/</loc>
    <lastmod>2026-04-03T17:50:14.772Z</lastmod>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/blog/tag/security-engineering/</loc>
    <lastmod>2026-04-03T17:50:14.772Z</lastmod>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/blog/tag/agentsh/</loc>
    <lastmod>2026-04-03T17:50:14.772Z</lastmod>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/blog/tag/software-development/</loc>
    <lastmod>2026-04-03T17:50:14.772Z</lastmod>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/blog/tag/ai-agents/</loc>
    <lastmod>2026-04-03T17:50:14.772Z</lastmod>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/blog/tag/agentic-workflows/</loc>
    <lastmod>2026-04-03T17:50:14.772Z</lastmod>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/blog/tag/ai-safety/</loc>
    <lastmod>2026-04-03T17:50:14.772Z</lastmod>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/blog/tag/autonomous-systems/</loc>
    <lastmod>2026-04-03T17:50:14.772Z</lastmod>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/blog/tag/execution-layer-security/</loc>
    <lastmod>2026-04-03T17:50:14.772Z</lastmod>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/blog/tag/kill-chain/</loc>
    <lastmod>2026-04-03T17:50:14.772Z</lastmod>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/blog/tag/beacon/</loc>
    <lastmod>2026-04-03T17:50:14.772Z</lastmod>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/blog/tag/mcp-security/</loc>
    <lastmod>2026-04-03T17:50:14.772Z</lastmod>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/blog/tag/defense-in-depth/</loc>
    <lastmod>2026-04-03T17:50:14.772Z</lastmod>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/blog/tag/claude-code/</loc>
    <lastmod>2026-04-03T17:50:14.772Z</lastmod>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/blog/tag/typescript/</loc>
    <lastmod>2026-04-03T17:50:14.772Z</lastmod>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/blog/tag/vercel-ai-sdk/</loc>
    <lastmod>2026-04-03T17:50:14.772Z</lastmod>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/blog/tag/secure-sandbox/</loc>
    <lastmod>2026-04-03T17:50:14.772Z</lastmod>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/blog/tag/supply-chain-security/</loc>
    <lastmod>2026-04-03T17:50:14.772Z</lastmod>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/blog/tag/mcp/</loc>
    <lastmod>2026-04-03T17:50:14.772Z</lastmod>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/blog/tag/glassworm/</loc>
    <lastmod>2026-04-03T17:50:14.772Z</lastmod>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/blog/tag/context-engineering/</loc>
    <lastmod>2026-04-03T17:50:14.772Z</lastmod>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/blog/tag/agent-rules/</loc>
    <lastmod>2026-04-03T17:50:14.772Z</lastmod>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/blog/tag/vulnerability-research/</loc>
    <lastmod>2026-04-03T17:50:14.772Z</lastmod>
  </url>
  <url>
    <loc>https://www.canyonroad.ai/blog/tag/command-injection/</loc>
    <lastmod>2026-04-03T17:50:14.772Z</lastmod>
  </url>
</urlset>
