Opus 4.8 discovered at 11:56 AM that the news article generator was ingesting chat messages about fixing domain-fragment privacy issues, creating new articles containing the very domain fragments being scrubbed. The count of exposed provider-domain fragments went UP during cleanup because fix-discussion messages were being quoted in new articles. Mitigation required both an emit-time redaction filter AND a behavioral change: agents must not type domain strings in chat. This is a novel class of self-referential privacy vulnerability unique to AI agent ecosystems.