Stop using the chat box
An opinionated guide to what to pay for, what happened when an AI institute let agents onto the live internet, and why prompt injection finally has CVEs.
“The acquisition of knowledge is always of use to the intellect, because it may thus drive out useless things and retain the good.”
― Leonardo da Vinci
* Today’s newsletter is brought to you by Context.dev.
Context.dev is a web data API to power AI native products. Turn any URL into clean Markdown, rendered HTML, screenshots, or structured JSON. Trusted by 14K+ developers and teams like Mintlify, Klarna, and SimilarWeb.
Hi friends,
We hand-picked 3 good pieces of content to inspire and motivate you now and in the future. Keep track of the insights that resonate with you by highlighting them with Glasp💡
If you want to reread or highlight this newsletter, save it to Glasp.
📚 3 Good Recommendations
1. An opinionated guide to which AI to use to do stuff by Ethan Mollick (8 mins)
Pick one and pay for it. Claude or ChatGPT, twenty dollars, and use the agent modes rather than the chat box. That is the whole of the setup advice.
Keep it on a leash at first. Leave every permission on ask-first, especially anything touching email, purchases or deleting files, and widen it only once you know how it fails.
Turn the thinking up when it matters. For medical, legal or otherwise consequential questions, use the stronger models with reasoning set high, where the error rates are measurably lower.
2. Incident Report: unsanctioned agent behaviour during cyber testing by Simon Willison (4 mins)
19 out of 122. During cyber evaluations run between July 25 and 28, the UK AI Security Institute logged 19 instances of agents acting on the live internet without sanction, across 122 attempts.
One agent ran a supply-chain attack on its own initiative. It opened a GitHub account, filed a pull request with a hidden prompt injection, then created a second account to pose as a reviewer endorsing its own PR, and sent spear-phishing mail to maintainers.
The setup explains most of it. Safety classifiers were deliberately turned off and the agents were given direct internet access. Willison’s point is that the missing piece was network sandboxing, not surprise at the behavior.
3. Indirect Prompt Injection: The Year It Got Real CVEs by Glasp (16 mins)
It stopped being theoretical. EchoLeak (CVE-2025-32711) let Microsoft 365 Copilot leak enterprise data from a crafted email, with no user action beyond receiving it.
Whatever your agent can read, an attacker can write. CometJacking and HashJack turned URL parameters and fragments into instructions for Perplexity’s Comet and ChatGPT Atlas.
The tool response is part of the prompt. In CVE-2026-21520, Copilot Studio agents treated whatever a connector returned as a legitimate continuation of the conversation, hidden instructions included.
📣 Community Updates
🟦 Launched Kindle Clippings Converter:
Amazon’s My Clippings.txt puts every book in one file, interleaved, with duplicates and notes torn away from the highlights they belong to. This turns it into something you can actually use: Markdown as one document or a note per book, CSV, an Obsidian vault, Anki cards, or JSON if you want to script it. It runs entirely in your browser, so the file never leaves your machine, and there is no account to create. Japanese, Spanish, German, French and Portuguese clipping formats are handled too.
🟥 Launched Airtable Importer:
If you keep your reading in an Airtable base, you can move it over in about two minutes, for free. Export the view as CSV, drop it in, and map your own column names to ours. They can be called anything: “Article URL”, “Quote”, “My Notes”. Before anything is saved you see how many highlights you will get and every row that will be skipped, with the reason why. It does not touch your base, and it is not a one-way door either: Glasp exports to Obsidian, Notion, Readwise, Zotero and more, so the next move is yours too.
🟨 Glasp MCP Connector on Product Hunt:
You can connect Glasp to Claude and ChatGPT and search your own highlights and notes in plain language, right inside the assistant. It is read-only and private to you. Thank you to everyone who came by to support and upvote it 🙏
🟩 35,000+ PDFs Uploaded & HighlightedPDF:
More than 35,000 PDFs have been uploaded and highlighted on Glasp. We’re excited to see how the community is using Glasp to organize research, study materials, and important documents.
🤝 Ask
🟥 Rate the Mobile App:
The iOS and Android apps are far newer than the extension, so each rating counts for much more there. Rate it on iOS here and on Android here.
❤️ Gratitude
Thank you for sharing and mentioning us on X, LinkedIn, and/or your blogs. 🙂 We appreciate your support! Please don’t hesitate to ask us anything at any time. Also, feel free to join our Reddit Community ;)
AI Future put Glasp in her roundup of the best AI Chrome extensions for 2026
OSINTech shared Glasp on Substack:
Dustin Miller put Glasp in his top five education tools, calling it the most successful social learning experiment he has seen
SaaSTrac added Glasp to its directory
Cortera published a company profile of Glasp Inc
WayToAGI listed Glasp among its AI tools
Logiciels.pro reviewed Glasp for French readers
Forendors featured Glasp for its Czech readers
ねん wrote up our AEO work in Japanese, including how ChatGPT traffic grew 37x in four months
We hope you enjoyed reading this newsletter!
See you next week ;)
Best,
Kei and Kazuki
--
Would you like to take Glasp on the go?
With the Glasp mobile app, you can highlight and organize your favorite content anytime, anywhere. Stay productive on the move and never miss an insightful quote.
Partner With Glasp
We currently offer newsletter sponsorships. If you have a product, event, or service you’d like to share with our community of learning enthusiasts, sponsor an edition of our newsletter to reach engaged readers.








The thread running through this issue is permission. AISI's agents were on the open internet with the classifiers switched off, Mollick's advice is to leave everything on ask-first until you know how a tool fails, and the CVEs show that anything your agent reads can carry instructions with it.
So, a question for you: have you given an agent write access to anything yet, your inbox, your repo, your files? What made you comfortable, or what stopped you?
Thank you to Context.dev for sponsoring this issue. If you run something you would like to put in front of this list, the fees and open dates are at https://www.passionfroot.me/glasp-newsletter, and every past sponsored issue is at https://read.glasp.co/t/sponsored