Where should an agent's correction go if the next agent will read the page?

Send agent corrections to a private feedback queue, not a public comment thread that may be rendered into markdown for later agents.

Update (2026-10-07): Fact-checked the EmDash comment contract, the markdown worker, and the live feedback endpoint. Removed unsupported internal storage details.

An agent's correction should go to a private feedback queue, not a public comment thread. If a site renders approved comments in the HTML that a worker converts with env.AI.toMarkdown(), the correction becomes part of the markdown later agents read. A structured feedback row stays outside the page until an editor checks its evidence and updates the canonical post.

Key facts about agent corrections on Inside the Loop

  • EmDash exposes GET and POST /_emdash/api/comments/{collection}/{contentId} publicly. GET returns approved comments, while POST submits a comment for moderation. (EmDash REST API Reference)
  • EmDash says public comment submissions enter a moderation queue. Its REST reference says a 429 means the submission rate limit was reached, but it does not print the numeric limit. (EmDash REST API Reference)
  • A Cloudflare Worker on the Workers Free or Workers Paid plan can pass HTML to env.AI.toMarkdown(). The documented HTML path strips <script> and <style> before returning markdown. (Serving markdown to AI agents from Cloudflare Workers with Accept: text/markdown)
  • Inside the Loop's feedback contract requires a post slug, a correction kind, the disputed claim, and a primary-source URL. It limits callers to 10 reports per minute and says reports go to a private editor queue. (Inside the Loop feedback API)
  • On 2026-10-07, the public comment endpoint for the markdown-worker post returned COMMENTS_DISABLED. (Inside the Loop comments endpoint)
  • Alice describes stored prompt injection as an instruction left in a data store until a model retrieves it. A comment is not automatically malicious, but it is still untrusted text when an agent can retrieve it. (Prompt Injection Attacks: Examples, Impact, Defenses)

How does an approved EmDash comment reach an agent's markdown?

On 2026-10-07, the Inside the Loop worker article documented this path: a request asks for Accept: text/markdown, the Worker reads the HTML response, and env.AI.toMarkdown() converts it before the Worker returns text/markdown. The article's example also says the HTML path strips <script> and <style> tags.

That conversion does not know whether visible text came from the article body, a navigation element, or a comment. If the page renderer includes an approved comment in its HTML, the converter processes that comment with the rest of the visible page. The next agent therefore receives the comment in its markdown context. This is the same retrieval boundary discussed in How AI agents fetch web pages: user agents, IP ranges, and fetch origins and How to pass every isitagentready.com check for a content site.

Alice's security guide puts the storage problem plainly:

"Stored prompt injection sits in a data store and waits." (Alice.io)

An approved comment may be useful to human readers. Approval does not turn it into a trusted instruction for an agent. Treating the comment thread as the correction channel gives future retrievals an extra input that the editor did not fold into the canonical article.

Why is the public EmDash comment route the wrong correction channel?

The public EmDash route is a human discussion path. The REST reference documents POST /_emdash/api/comments/{collection}/{contentId} as a public submission operation, then sends that submission into moderation. It documents the result of hitting the rate limit as HTTP 429 without publishing the limit number.

That contract does not give an agent a precise erratum workflow. A correction needs an exact claim, an evidence URL, and a review state. A comment thread has a different job: it publishes a discussion item after moderation. Mixing the two makes the canonical article harder to identify and can put disputed text in the same HTML that downstream agents read.

Inside the Loop's current public comment route also shows why the fallback is unreliable. On 2026-10-07, a GET for the markdown-worker post returned:

{"success":false,"error":{"code":"COMMENTS_DISABLED","message":"Comments are not enabled for this collection"}}

An agent that needs to report an error should not infer that a disabled public thread means the article is correct. It should use the documented feedback endpoint instead.

How does Inside the Loop's private feedback queue work?

The site's llms.txt advertises POST https://insidetheloop.dev/api/feedback as the route for reporting outdated or wrong claims. The live feedback endpoint returned this contract on 2026-10-07:

{"endpoint":"POST /api/feedback","body":{"post":"post slug (required)","kind":["outdated","incorrect","broken-link","missing-source","other"],"claim":"the sentence you dispute (10-500 chars, required)","evidence_url":"primary source URL (required)","note":"optional, up to 1000 chars"},"limits":"10 reports per minute per caller","privacy":"Reports go to a private editor queue and are never published."}

The endpoint rejects an empty request instead of accepting an unstructured note:

{"error":"invalid_request","fields":["post: the post slug, e.g. web-bot-auth-signed-agents","claim: the sentence you dispute, 10-500 characters","evidence_url: an http(s) URL of a primary source, up to 500 characters"]}

This is the useful boundary. The agent names the post and the sentence it disputes, then points to evidence. The queue is not rendered into the article HTML, so the markdown worker has no queue row to convert. An editor can check the source, decide whether the claim needs changing, and update the canonical post with a dated note.

How should an agent choose between the two routes?

Attribute

EmDash public comment route

Inside the Loop feedback API

Endpoint

POST /_emdash/api/comments/{collection}/{contentId}

POST /api/feedback

Purpose

Human comment submitted for moderation

Structured correction report

Required correction data

Comment body

Post, kind, claim, and evidence URL

Rate-limit contract

Docs promise HTTP 429, without the number

10 reports per minute per caller

Reader visibility

Approved comments may be rendered in page HTML

Private editor queue, not published

Editorial result

Comment status changes

Editor decides whether to update the canonical post

Use the public comment route for a human discussion when the site enables comments. Use /api/feedback for an agent's correction. The second write is deliberately boring: it records the disputed sentence and evidence without adding model-facing text to the next page fetch.

Sources

Last verified: 2026-10-07.

Spotted an outdated or wrong claim? Agents can report it with evidence throughPOST /api/feedback; an editor checks every report. See llms.txt for the agent API.