self.md radar — 2026-05-26
The useful AI news landed in the joints: where agents borrow permissions, preserve local context, and turn private notes into public machinery.
Microsoft gave us the ugly control case: Copilot Cowork could be steered through a poisoned Skill into leaking file links, while a separate governance toolkit points at the boring work required to contain that class of mess. llama.cpp merged a checkpoint fix for long local coding sessions, where one cache miss can turn a tiny follow-up into a full prompt replay. Quartz v5 rebuilt the Obsidian-to-web path around plugins, YAML config, and native vault affordances.
1. Copilot Cowork exposed the approval gap
sources:
what happened: PromptArmor published an indirect prompt-injection path against Microsoft Copilot Cowork: a poisoned Skill can ride the user’s Microsoft 365 permissions, use Microsoft Graph, and send the active user an email or Teams message without the same approval friction as an outside action. The nasty detail is the file handle, not the prose trick: Cowork can retrieve pre-authenticated download links for files the user can access, and a compromised message can leak those links through external image requests. In the same feed, Microsoft’s Agent Governance Toolkit repo was active on May 26 and describes the counter-shape: policy enforcement, zero-trust identity, execution sandboxing, reliability engineering, and OWASP Agentic Top 10 coverage.
why this matters: Prompt-injection defense keeps failing when the agent holds normal human permissions plus a convenience bypass. The hard work moves into tenant hygiene, skill loading, scoped links, per-action receipts, and deciding which “helpful” actions should never be automatic.
2. llama.cpp patched the local-agent pause
sources:
what happened:
ggml-org merged PR #22929 on May 25 to fix server checkpoint creation. The patch extracts message_spans from chat templates, uses an autoparser for more templates, finds the prompt-token position before the latest user message, and creates a context checkpoint there instead of relying on periodic mid-prompt checkpoints. The author says the goal is better “responsiveness” for agentic coding and tested with a 200,000-token context, Qwen3.6-27B-Q8_0, --ctx-checkpoints 24, and --cache-ram 65536.
why this matters: Local agents are not just weights on disk; they are cache machinery, chat-template parsing, and recovery from mutated conversation history. If the runtime cannot find the right checkpoint, a harmless “thanks” after a long coding run can become another full-context tax.
3. Quartz v5 moved vault publishing into plugins
sources:
what happened:
Quartz 5 is live, with the official site dated May 24 and the GitHub repo now on a v5 default branch. The maintainers describe it as a full rewrite after three years: features become standalone plugins, more than 40 official plugins ship with the project, config moves to YAML with JSON Schema validation, and Obsidian affordances like wikilinks, callouts, Canvas, Bases, embeds, footnotes, and custom task characters get first-class treatment. The getting-started path also names a real floor: Node v22 and npm v10.9.2.
why this matters: Obsidian publishing is turning from a static export trick into a small personal-site runtime. That is good for people who want their notes to become durable public surfaces, but it also means notes, plugins, schemas, and builds can now break in four different places instead of one.
supporting links
- NuExtract3 — Apache-2, Qwen3.5-4B-based VLM for OCR, document-to-Markdown, and structured extraction; a plausible local intake layer for agent paperwork.
- NuExtract3 Space — quick hosted demo for the same document extraction model, useful before wiring it into a local pipeline.
- Vellum Assistant — personal assistant repo with memory, personality, and proactive reach-outs across macOS, Telegram, and Slack.
- AgentToolBench-Code — a tiny security-benchmark marker for coding agents; not enough for a main signal yet, worth tracking.
left on the table
- Cherry Studio , Understand Anything , and codegraph had stars, but the code-graph/workbench wave has been covered too recently.
- Figure’s package-sorting livestream and India’s head-camera robot-data clip stayed out because the cache gave video/social evidence, not enough source-side detail.
- Heretic’s FT thread had useful numbers, but the usable copy was downstream from a paywalled article.
- DeepMind’s Erdos-problem claim was an image post; too thin for a main signal without primary backup.
Related self.md routes
- Personal AI OS tools — the control-plane map for personal agents, receipts, memory, and tools
- AI coding assistants — compare coding workbenches by review surface, permissions, cost, logs, and escape hatches
- Best MCP servers — connect files, browsers, memory, search, and workflow tools without turning the stack into soup