self.md radar — 2026-05-23
The AI operator tax showed up in places that do not care about demos: security queues, repo contribution rules, and per-token routing tables.
Anthropic says Mythos found a five-digit pile of serious bugs. SQLite writes down what agents may and may not do in its source tree. DeepSeek turns a temporary discount into permanent routing math. The useful through-line is not autonomy; it is accounting.
1. Glasswing made security triage the scarce part
sources:
what happened: Anthropic published its first Project Glasswing update, saying about 50 partners used Claude Mythos Preview to find more than ten thousand high- or critical-severity vulnerabilities across critical software. In the open-source scan, Mythos estimated 6,202 high- or critical-severity issues out of 23,019 total findings; 1,752 of those serious findings were assessed, 90.6% were valid true positives, and 62.4% were confirmed as high or critical. Anthropic says it has disclosed 530 high- or critical-severity bugs to maintainers so far, with 75 patched, and introduced Claude Security as the harness around codebase mapping, scanning subagents, triage, and reports.
why this matters: Finding bugs at model speed is only half the job; the slow part is reproducing, disclosing, patching, and getting users onto fixed builds. Autonomous security work now needs an incident room, not a victory lap.
2. SQLite gave agents a written boundary
sources:
what happened:
SQLite added a prototype AGENTS.md file: 125 lines of instructions for AI coding agents in a public-domain C project that uses Fossil, not Git. The sharp line is not buried: SQLite “does not currently accept agentic code,” but will accept agentic bug reports with reproducible tests, while demo patches can serve as documentation for humans. Around the same window, Superset pitched worktree-based orchestration for many CLI agents, and OpenRig described YAML-defined agent topologies with persistent identity and shared memory.
why this matters: Serious repositories are not just inviting agents in; they are writing contracts about where agents stop. The useful agent surface is becoming rules, test commands, provenance, and handoff proof that a maintainer can actually use.
3. DeepSeek put the router inside the invoice
sources:
what happened:
DeepSeek’s pricing page now lists deepseek-v4-flash and deepseek-v4-pro with both OpenAI-format and Anthropic-format base URLs, 1M context, and a 384K maximum output. The page says V4 Pro API pricing will be officially adjusted to one quarter of the original price after the 75% promotion ends on 2026-05-31, with the current promo table showing $0.003625 per 1M cache-hit input tokens, $0.435 per 1M cache-miss input tokens, and $0.87 per 1M output tokens. Models.dev, meanwhile, is packaging model specs, pricing, and capabilities into an open-source database with an API that opencode already uses internally.
why this matters: Once providers imitate each other’s APIs, model choice becomes routing policy backed by a bill. The operator edge is knowing which task deserves the expensive path, which one can ride cache hits, and when the harness should swap models without turning the workflow into soup.
supporting links
- CoreMem — stores portable “mems” that agents can load through URLs, scoped links, and MCP, with human approval before updates are written.
- NuExtract3 — Apache-2.0 4B vision-language model for structured extraction, OCR, and document-to-Markdown pipelines.
- Obsidian pdf-to-md thread — handwritten PDFs and images become Markdown inside the vault, including math output and support for OpenAI, Claude, Gemini, and Qwen.
- Simon Willison on the memory squeeze — HBM demand is pushing consumer-device memory into the same accounting conversation as model inference.
left on the table
- Plex’s lifetime price jump and the Jellyfin migration thread were a strong custody story, but this edition stayed on AI operator mechanics.
- Figure AI’s 200-hour package-handling claim had reach, but the cache surfaced it as a Reddit video item without enough primary operational detail.
- codegraph and Claude plugins stayed out because the seen ledger already carried those exact URLs this week.
- The NuExtract3 and Obsidian document-intake pair nearly became a main signal, but the Glasswing, SQLite, and DeepSeek items had cleaner deltas today.
Related self.md routes
- Personal AI OS tools — the control-plane map for personal agents, receipts, memory, and tools
- AI coding assistants — compare coding workbenches by review surface, permissions, cost, logs, and escape hatches
- Best Claude Code plugins — choose the Claude-specific extensions worth installing, and the ones to skip