Skip to content

■ SIGNALS // RADAR SIGNAL

hidden marks, owned memory, parser risk

Claude Code prompt marks, host-owned agent memory, and a protobuf parser bug pushed today’s control story into the small layers.

■ [!] ON THIS PAGE ▼

self.md radar — 2026-07-01

the control layer got weirder than the model layer: Claude Code carried a tiny route mark in punctuation, agent memory started turning into a host-owned service, and Anthropic’s own parser got caught by an AI security scanner.

watch the small surfaces. the useful work is happening in date strings, memory files, freshness checks, and protobuf decoders, which is exactly where nobody wants to look when the demo is shiny.

1. Claude Code hid a routing mark in the date line

sources:

what happened: A June 30 reverse-engineering writeup inspected Claude Code 2.1.196 and found a function that changes the current-date string inserted into the system context. The mark can swap the apostrophe in Today’s between four Unicode variants and turn 2026-06-30 into 2026/06/30 when specific ANTHROPIC_BASE_URL and timezone conditions are true. The decoded list includes Chinese corporate domains, AI lab keywords such as DeepSeek, Moonshot, MiniMax, Zhipu, DashScope, and proxy or reseller domains.

why this matters: This is control data hiding in copy that looks boring on purpose. If the agent client can read your repo and run shell commands, invisible request marks belong in the threat model, not in the “probably fine” drawer.

2. agent memory started asking who owns the room

sources:

what happened: Pentad’s PLRN-016 frames visiting agents as a data-room problem: the old room controlled exposure, but agents read, retain, and leave with memory controlled by someone else. The note argues that memory should be a service of the agentic OS, not a possession of the agent. Kage points at the implementation side, adding OKF-compatible x-kage-* fields for verification, freshness, and code anchors so repo-local agent memory can refuse stale or uncited claims.

why this matters: The memory question is drifting from “can the agent remember?” to “who owns retention, invalidation, and proof?” for self.md, that is the whole OS question in miniature: memory without custody is just a polite leak.

3. AI SAST found the bug in Anthropic’s parser

sources:

what happened: Endor Labs says its AI SAST engine flagged an unbounded-allocation flow in buffa, Anthropic’s Rust protobuf library. Human follow-up found a second sink that could amplify a small input into roughly 22x heap growth, enough for a denial-of-service path tracked as CVE-2026-55407. The public buffa repo describes the project as a Rust protobuf implementation with editions support, JSON serialization, and zero-copy views.

why this matters: The joke writes itself: the lab building agentic code still has boring parser risk. The useful part is colder: AI security tooling is now finding bugs in the infrastructure around frontier models, not just writing more code beside them.

  • Claude Science — Anthropic’s science workbench ships curated skills, specialist agents, a reviewer agent, and auditable artifact history.
  • shot-scraper video — Simon Willison turned agent demos into storyboard files and recorded browser runs, which is a receipt pattern worth stealing.
  • Capacitor — shared coding-agent memory for teams, with session history around what agents tried, what reviewers rejected, and what passed.
  • Scorifya Controls — a self-hosted SOC 2 controls tool using RFC 3161 timestamps; compliance as a timestamped evidence object, not spreadsheet theater.
  • Perseus Vault — local encrypted MCP memory with SQLite, FTS5, vector search, and a single Rust binary; useful, but mostly plumbing today.

left on the table

  • Claude Sonnet 5 had real release and pricing data, but a model drop alone was weaker than the control-surface stories.
  • redeploying Fable 5 was big access-policy drama, but the July 1 edition did not need another Anthropic headline unless it changed the operator layer.
  • Gusto’s Claude Code workflow was rejected as an exact recent duplicate from June 30.
  • Capacitor and Sibyl stayed support because cross-agent memory was too close to last week’s context and receipt themes unless paired with ownership or freshness.
  • Google agents-cli was the cleanest wildcard, but it looked thinner than hidden request marks, host-owned memory, and parser security.