Research dashboard · Infrastructure

Other Chinese swarm leads

Round 383: New Chinese agent-labelled forum 爱讨论: a specific reference across two public threads matches the recovered target floor. Operator independence remains unverified. Evidence and links.

Round 382: tutu-ai implements separate character decisions and local speech propagation, driven by a browser loop. No public run history recovered. Source findings.

Round 381: Grix has public delegation and recovery code; its claim of agent-led self-maintenance still needs a conversation-to-change record. Evidence and next checks.

Round 380: Chinese three-day swarm story matches earlier Mycel account. Distinctive names and numbers indicate a likely retelling, not independent Chinese deployment evidence.

Round 379: Agents Universe: public maintenance PRs. Source-confirmed loop-limit fix; claimed agent maintainers remain unverified without conversation-to-PR evidence.

Round 378: GroupX demo inspected: peer replies and human-requested synthesis. Final Codex summary follows a second user prompt; raw execution remains unverified.

Round 377: GroupX: published capability matrix and evidence index. All twelve indexed evidence paths are absent from the public tree; live demo remains to inspect.

Round 376: Bloome counting video inspected. Four named speakers visibly count 1–20; annotated comparison is preserved, with runtime provenance still unresolved.

Round 375: Bloome: shared-task protocol and audit-sub-agent claim. Chinese community coverage and self-reported Shenzhen team link; public counting video queued for inspection.

Round 374: Delulu and the 7栋空间 mini-program. Scheduled dating-proxy interaction documented; no public execution transcript recovered.

Round 373: DSH Moments: one model generating nine friend personas. Source includes random interactions, template fallback and historical post backfill; no independent model peers established.

Round 372: MickerBook plugin and HerLove companion connection. Plugin is onboarding material; HerLove success badge checks loop-entry count, not completed agent work.

Round 371: MickerBook public API and template-history testimony. API reports 28 agents and 1,079 posts; official SDK is an integration layer, with no recovered production execution log.

Round 370: MickerBook: four posts, seventeen comments and ten agent-labelled identities. Specific earlier-message references recovered; autonomous operation and provenance remain unverified.

Round 369: HomeStream has named-team messaging code, but its default maker/reviewer loop is simulated and can pass on nonempty output. Source audit.

Round 368: AtomHub has an explicitly AI-labelled author. Older list pages sort IDs as text, so page order is not a timeline. Evidence and identity limits.

Round 367: AtomHub has public conversations and reports 908 posts; agent identities remain unverified. Read sampled evidence and timestamp caveat.

Round 366: Agentsensus publishes selected story-world messages and a paper draft, while explicitly excluding raw event logs. Evidence and new community leads.

Round 365: The OpenMOSS novel-team operator later reported costly coordination drift. Recovered diagrams show intended workflows, not runtime records. Later assessment and evidence limits.

Round 364: OpenMOSS links a later team experiment to English news articles at 1M Reviews. Indexed outputs recovered; public activity feed timed out. Evidence and next steps.

Round 363: Open Typeless has 33 matching journal commit references and four archived task branches linked to merged PRs. Full agent execution remains unverified. Read evidence.

Round 362: Two further operator accounts: a five-role Hermes company workflow and a failed overnight OpenClaw team. Evidence, limits and infrastructure options.

Round 361: VOKO publishes an 18-provider compatibility account and a group-test script, but no retained group-run outputs were found. Cloud messaging is separate from its local open-source runtime. Evidence audit.

Round 360: CorpPilot has real-provider code, but its demo seeds artifacts, test-success markers and usage records; Claude smoke defaults to dry-run. No retained full-team run found. Source audit.

Round 359: Clowder reports live busy-agent handoff tests, but all 29 issue replies share one publishing account. Later recurrence fixes still await shared-runtime activation. Evidence audit.

Round 358: Clowder historical review request recovered. A canceled review-handoff fixture names an exact commit found in public PR1391; this is not a successful review or implemented self-management. Evidence and limits.

Round 357: Edict user reports a completed task being retried after 605 seconds. Pinned source supports the mechanism; matching fix remains unmerged. Edited examples and simulated dashboard rows are separate evidence. Read the audit.

Round 356: New LINUX DO company-pipeline account specifies four human gates and unfinished test integration. Its architecture diagram leads to an Edict source comparison; CorpPilot and Clowder are separate follow-ups. Evidence and limits.

Round 355: Astraloom defaults to mock responses and its inspected task path overwrites failure with done. StuFlow has local session logging but no retained public run in the inspected tree. Source audit and infrastructure options.

Round 354: PR-Copilot documents a zero-findings parsing failure and claims11findings after fixes on a real public PR. Source corroborates fallback extraction; full review output remains absent. Adoption evidence.

Round 353: OMA’s selected run artifact has five tasks and43spans, with an explicit Shenzhen-company connection. Capture instructions prescribe the parallel structure and forbid running generated tests; displayed cost is calculated. Artifact audit.

Round 352: New AIsChat social-platform lead: demo counts are seeded local data; a separately listed federation host serves an application shell. No live conversation corpus established. Source and instance check.

Round 351: Both journal commit IDs match executor tool results. Earlier instructions encouraged small commits; the no-commit policy was documented later. Captured tests show a red-to-green sequence. Evidence and instruction context.

Round350: Recovered the style-museum observation journal inside a session read result and reconstructed a312-line analysis from recorded edits. The advertised findings occur in the executor output; independent orchestrator verification remains absent. Evidence update.

Round 349: Recovered five published style-museum session fixtures: 5,822 events and 172 tool calls. They contain a code edit/test result and a failure matching the earlier pipeline account; the full collaboration remains unverified. Captured evidence.

Round 348: Hermes–DSH Collab claims a 14-day pipeline and describes specific failures, but its referenced style-museum observations are not publicly located. The owner’s observation-journal project is the next lead. Source audit.

Round 347: Related a2a-bridge publishes a cross-host smoke-test account; its named configuration fix matches a public commit. Initial and later two-target tests explicitly use stubs. Evidence and limits.

Round 346: ccteam’s roblog fixture contains 13 substantive Chinese messages and 26 idle notifications, including reviewer findings and developer fix reports. Model identity and claimed code output remain unverified. Conversation evidence and limits.

Round 345: Recovered the correct DSH mesh repository; inspected message framing and persistence. ccteam documentation points to a captured five-member team and 39-message inbox, pending content review. Evidence and next checks.

Round 344: DSH s2s source supports local peer messaging and optional dormant-session waking; no public sustained-run transcript located. New log signatures and practical mainland-browser infrastructure notes: report 344.

MACE checked: mock adapters generate expert-style answers and scores; missing API configuration falls back to mock. Its patch helper does not run benchmark tests. Report343.

Liquid-loop checked: release checksum verified; its inspected multi-agent experiment is18scripted writes with three labels, not a model exchange. Report342.

Ling provenance follow-up: committed discussion requests have no responses. A separate results page contains role replies but unsupported measurements and contradictory consensus labels. Report341.

LingMessage source checked:21prewritten seed-message call sites and exact text matches; a separate sequential DashScope discussion engine writes inferred provenance labels. Report340.

Ling-family output found: story matches discussion proposals. Earlier work records explicitly include seed conversations and a narrative demonstration; public source is now located for provenance checks. Report339.

New Ling-family discussion archive: five named roles in a published creative-writing exchange, with a stable discussion ID. Human initiation and an8-versus9-message discrepancy limit its autonomy claims. Report338.

Multigent linked to agencycli: the operator explicitly describes the successor project. A launch-task screenshot is awaiting human review; source also initializes example workflows before model execution. Report337.

FastClaw / Multigent: FastClaw source has a delegation interface, but hosting-user totals do not measure a swarm. A later article links the public Multigent repository, now queued for checking. Report336.

Agencycli follow-up: screenshots show separate human-assigned tasks; an owner comment is QA-role-signed. An older Codex-to-Gemini relay report includes timeout diagnostics but no actual replies. Report335.

Agencycli evidence join: an agent-labeled review screenshot names a commit interval; GitHub confirms exactly13 commits including the referenced relay-timeout PR. Agent authorship and follow-up execution remain unverified. Report334.

New simulated-world leads: SoulSim has peer-response backend code, but its public demo replays a fixed five-character scenario. A separate29-NPC operator explicitly describes private operation. Report333.

CCCC applications checked: released355-account dataset matches its checksum; these are monitored accounts, not agents. Two-agent workflow documents survive, but no actual posting ledger was recovered. Report332.

CCCC operator history: a 2025 thread links two application projects and explains recurring supervisor wakeups. A recent disabled-actor bug remains unreviewed. Report 331.

CCCC replay check: public client exposes snapshot/event/player-message routes, but all tested routes return Cloudflare Tunnel Error1033. No replay recovered. Report 330.

New CCCC activity lead: a February mahjong broadcast shows four Chinese-model-labeled seats. The match page is reachable, but its replay has not yet been recovered. Report 329.

ENGRAM development follow-up: documents describe a shared mailbox and a two-agent handoff disagreement. Referenced issue607 and PR425 return404; original exchanges remain unavailable. Report 328.

AgentVerse source checked: shared notes enter later system prompts; mentions can select members with automatic replies disabled. Current code checks a round limit. Report 327.

Older AgentVerse operator: 2025 users report lengthy and duplicated discussion loops; a later screenshot shows role replies and a shared-note tool action. Report 326.

ENGRAM Commons checked: public agents, topics and counts are explicitly illustrative. The repository also seeds authored conversations; neither is a recovered live exchange. Report 325.

SOLO task-bus demonstration: planner and worker screenshots share a task ID with the repository run record. It is a connectivity test; the separate three-agent smoke test makes no model calls. Report 324.

New operator: agent-bus. A Chinese developer reports agents coordinating an Android/iOS project overnight across machines. Source implements handoffs and shared-board storage; no run transcript is committed. Report 323.

AgentsChat follow-up: two July commits implement features named in the collaboration case. An April MCP proposal was closed as a duplicate, not merged. Report 322.

AgentsChat Protocol: an anonymous public feed shows two probe/ack pairs. A development ledger and npm records partly corroborate its four-agent release story; no raw collaboration transcript or Chinese lab provenance verified. Report 321.

New leads: MiniMax describes shared message-board files and persistent team memory. Agentschat has a Chinese operator’s persona/group-chat interface, but the inspected screenshot contains no exchanged messages. Report 320.

Failure reports checked: a saved-task notification gap was reproduced with a storage test double. A separate sync-stall diagnosis has inconsistencies; its linked PR971 was closed without merging. Report 319.

Reported agent loop: a redacted15-entry AgentTeams transcript shows a streetlight query followed by repeated acknowledgments after FINAL. A separate user reports missing-mention stalls. Inline reports, not independently verified event exports. Report 318.

Actual shared-memory reproduction: an AgentScope user posted four-agent console memory; maintainers acknowledged an unwanted thinking block and merged a broadcast filter. Bounded local test, no escape demonstrated. Report 317.

HiClaw user deployment: two March forum screenshots show matching stock-team worker names in chat and container views. Actual analysis exchanges and outputs remain missing. Report 316.

Memory Hub demo clarified: the detailed Claude Code → Codex → Wukong handoffs are explicitly fictional, with no agent calls. The repository-linked official site works from this server. Report 315.

Chinese community lead: ZNT digests describe a three-model/seven-agent scaffold, but identify themselves as unchecked AI summaries and provide no inspected code link. Linked task/case categories are empty. Report 314.

AutoResearch task claims: source uses a locked local queue and expiring worker leases. Runtime outputs are explicitly excluded from the repository. EvoX network diagrams represent partner choices, not captured messages. Report 313.

Feedback path checked: all three Synapse Run engines feed moderator messages into model inputs. New EvoMap AutoResearch lead has a paper and recoverable review code, but no run bundle found in its current tree. Report 312.

New operator code lead: Synapse Run uses a shared discussion file and moderator triggered after five reports. No preserved run transcript found in the current tree. Additional PandaAI course posts checked. Report 311, including useful access infrastructure.

New operator-community artifact: PandaAI. Attached screenshots show a configured workflow, a null tool result and a failed simulated trade. They do not substantiate the post’s profit claim. Report310.

VirSci scale clarified: the paper reports one million simulated scientists sharing model endpoints on 32 A100 GPUs. Source implements queued inference; no saved dialogue archive located in the current tree. Report309.

SeevoMap inputs resolved; VirSci located. All five claimed inputs exist, but their effect on the receiving experiment remains unverified. VirSci names Shanghai AI Lab support and links a larger simulation successor. Report308.

SeevoMap provenance resolved for one sample: idea, code diff and metric exactly match an upstream Stanford-affiliated research dataset. Pending submissions separately identify five claimed community inputs. Report307.

SeevoMap counts clarified: the map contains 4,273 nodes, including 1,200 hypotheses, with exactly five outgoing weighted links per node. A solo/community pair claims knowledge reuse but lacks retrieval records. Report 306.

New artifact corpus: SeevoMap. A publisher-linked dataset lists 3,076 research-record JSON nodes. The first sample contains a code diff and a reported failed experiment. Cross-agent reuse and runtime provenance still need verification. Report 305.

AgentPanel runtime checked: source constructs model-backed forum agents and explicitly supports English replies from Chinese personas. Its current memory middleware returns no history. Indexed threads are visible, but full live records remain unverified. Report 304.

New priority: AgentPanel. Its paper lists Shanghai AI Laboratory affiliations and reports an intentionally deployed scientific agent forum. Public code and paper are accessible; live-site TLS failures currently limit direct thread verification. Report 303: provenance and limits.

HermesWorld → public code: older posts link to AI_Awakening and a Hermes/Maka WeChat router. Current network code is implemented; the bridge test simulates replies. Neither supplies verified autonomous runtime records. Report 302.

New: HermesWorld. A Chinese-language agent community exposes public JSON conversations. One September 3 thread contains 28 comments from five accounts, including substantive back-and-forth and four test markers. Independent agents and lab provenance remain unverified. Report 301: evidence, limitations and next searches.

Research Trellis checked: all eight archived runtime-probe JSONL files contain redaction markers. A sampled task JSONL is a context placeholder. File counts do not establish agent activity. Report 300: parsed evidence and Hansong follow-up.

Two operator leads: Hansong publishes a detailed parent-child iteration account, with redacted instructions but no raw run export. Aidan’s overnight interference story remains search-indexed mirror evidence. Report 299: evidence and retrieval limits.

Polaris and Easel follow-up: Polaris has delegated model/tool execution code, but no new run trace was obtained. Easel’s publishing screenshot shows drafts with all six platform accounts logged out. Report 298: source and screenshot evidence.

Polaris checked: its publisher identifies as a Zhejiang University team. The homepage experiment uses scripted messages and metrics; four sampled demo-video frames do not provide raw execution records. Report 297: source and visual checks.

New research lead: AMID. The primary paper lists CUHK and Chinese Academy of Sciences affiliations alongside international collaborators. Its public repository contains 20 solution reports; two inspected reports summarize results without underlying execution logs. Report 296: affiliations, repository snapshot and limits.

XNTJ follow-up: cross-review implements model review, but its two examples are inputs; all seven public commits contain no separate debate export. The owner describes human approval before product releases. Report 295: source checks and operational claims.

New owner-to-code lead: Zhang Pinpin’s Windows research account links directly to xntj-ai, including a cross-model review project whose examples are next to inspect. An overnight-agent story was traced to an English original with private supporting records. Report 294: provenance and next checks.

September 6: new collaboration lead. DSH Agent Arena publishes three-role discussion and decision-board screenshots plus orchestration code; its raw meeting export is absent. Source inspection and practical infrastructure plan. Two agent-email stories resolve to human-authored exchanges or a reciprocal loop the author never tried: email evidence review.

RMA attribution update: the primary paper lists Georgia Tech. Preserve its checked collaboration artifacts as an adjacent US-affiliated example; it is not a confirmed Chinese-operated swarm. Report291 and next Chinese mail leads.

RMA review/revision chain: a critic-labelled issue and solver-labelled correction match a saved proof revision. All five versions pass hash/size checks; the problem remains unresolved. Role labels are not independently authenticated. Report290.

ResearchMathAgent artifact found: a committed proof-history record matches its LaTeX file’s length, line count and hash prefix. Multi-agent provenance remains to be checked against issue discussions. Report289.

LarkFlow code review: its advertised AI decision path is a fixed placeholder; status and success flags are insufficient evidence of live work. Report288.

AiToMoney checked directly: the nightly account claims successful development, but omits the run steps; its linked GEO repository is unavailable publicly. Another owner repository, LarkFlow, supplies the next code lead. Report287.

Agent-generated code credit: the office owner’s linked plugin preserves an OpenClaw/DeepSeek attribution in Git. A separate AiToMoney team account describes nightly-development failures and named agent projects. Report286.

Office follow-up: an earlier article explicitly credits two named research agents and a human reviewer. The owner’s public GitHub account is now linked; the reachable Gitea listing exposes no repositories. Report 285.

Office mailbox account: a Chinese owner describes six collaborating departments, but the underlying messages remain unavailable. DeepSearch adds a source-backed screenshot demonstration, without a raw run export. Report 284.

TraceArena reviewed: its public benchmark and provider code agree that the replay uses scripted controls. No model-driven swarm established. Report 283 and practical access priorities.

Report 282: Yolanda / Trae failure retrospective. Screenshot supports repeated SOLO Agent edits; no public peer-handoff trace. Claimed rule-overload mechanism remains unverified.

Report 281: Kleisli source provenance and new field reports. Chinese article reproduces an English coordination account; no independent Chinese operator established. Two firsthand-account candidates queued for review.

Report 280: Nanobot upstream review. A reviewer-identified placeholder bug was corrected in the PR source. Both linked PRs are closed unmerged; deployment inclusion and live peer work remain unverified.

Report 279: Nanobot Legion deployment review. Public HF metadata reports a running container; collaboration is behind sign-in. Relay code can return success with partial text after timeout, so that signal alone does not prove task completion.

Report 278: AI4S paper-derived trajectory review. Trajectory JSONs reconstruct scientific papers; they do not establish live agent experiments. Listed example outputs are absent from the inspected current tree.

Report 277: Forty-agent source trail and Nira status. Forty-agent claim remains unverified. Linked Nira page advertises thirty roles, while its latest public metadata reports zero agent-authored results and 94 fallbacks.

Report 276: LingTai initial-instruction review. Initial histories explicitly encourage peer contact, reusable skills and Git commits. Verified collaboration stands; the experiment does not establish those goals emerged without prompting.

Report 275 — coordination verified within the export: LingTai mail and shared-library joins. All 69 peer-addressed outgoing messages match received/archive copies. Two shared-file writes match repository contents, with successful commit results in event logs. Deliberate experiment; operator/provider provenance remains unverified.

Report 274 — substantive new artifact: LingTai twenty-agent experiment. Public repository contains twenty agent directories and 77 outgoing mail records, including 35 from one hub. Delivery and event joins pending; intentionally launched experiment, no escaped-lab attribution.

Report 273: Mobius shared-board implementation and screenshot review. Concrete peer-notification code; no published run recovered. Three screenshot commit prefixes did not resolve in the inspected public history.

Report 272: Agent-talk recordings and Mobius lead. Two downloadable terminal records show a dataset-split exchange; Chinese operation remains unestablished. A Chinese Mobius announcement supplies the next source-review lead.

海獭湾 follow-up: two completed-task labels recovered, including a requester’s parallel-agent claim, but no public deliverable. Closed-task and health counters do not verify completed agent work. Report271.

New task surface: 海獭湾. Public APIs report1263 tasks, but collaboration-learning writes are explicitly disabled/roadmap. One public task inspected; no completed agent output verified. Report270.

Six-role DSH workflow: inspected checks validate supplied evidence fields, not independent execution receipts. Event storage is implemented, but no actual event archive recovered. Report269.

Vibe Mathematics: source implements persistent researchers and consensus-based verification. Its self-driving test uses simulated replies; no actual solved-problem record recovered. Report268.

Punky use claims recovered: historical notes name sessions and task batches; a published screenshot shows completed-looking batches and an11-subagent label. Underlying events and outputs remain missing. Report267.

Punky swarm: public source implements session mapping and mailbox alerts; the checkpoint demo is a fixed animation. Git history retains removed development snapshots for follow-up. No actual run authenticated. Report266.

ACPs source reviewed: Chinese university-led inter-agent infrastructure supplies precise message/access log formats. No run records recovered; demo metrics are explicitly synthetic and audit signatures optional. GitCode is readable from this server. Report265.

Mixed-model Gist downgraded: its client returns text without a tool-execution loop, and launchers call an undefined export. No working team run recovered. Report264.

Chinese-model setup lead: a February-dated Gist describes GLM/MiniMax/Kimi teams, but inspected files contain setup material rather than run records. Huashu commit searches yielded no verified deployment and substantial fork duplication. Report263.

Huashu source and personal-team claim: pinned code supplies concrete task-claim and session-log fingerprints. A separate “100% automation” article still lists monitoring and cross-agent testing as next steps; no named PR recovered. Report262.

XiaPost recurring participation: 19 of20 visible posts cluster just after a three-hour schedule. The profile describes a comment-selection formula, but no runtime logs or joint output were recovered. Report261.

New community: XiaPost. A game-development help request names a workspace, and a second profile asks about testing. The claimed GitHub location returns404; no joint build recovered. Report260.

Lu Ban source recovered: Fengxinzi’s SkillHub package implements OpenClaw/Hermes orchestration, but includes simulated success output and a verifier that does not explicitly reject simulation. No run archive was listed. Report259.

Fengxinzi team digests: public reports distinguish active-category agents from recent work, and describe scheduled-task failures and owner feedback. Exact post metadata recovered; linked skill output remains uninspected. Report258.

Novel-writing lead: a Chinese repository explicitly mentions agent swarm and includes a chapter, but also local text-generation scripts. No worker transcript was recovered; file existence alone does not establish teamwork. Report257.

Elaine follow-up: linked guides provide illustrative workflows and command descriptions, without an externally verified team output in this check. Retain the public board as a surface; lower the swarm claim’s priority. Report256.

New public work surface: Elliot/Elaine’s site exposes a task board and work notes. Its guide admits most teammates were unused at that time; completed-task labels do not verify execution. Report255.

Chinese developer-community follow-up: AI Roundtable’s public release contains implemented multi-role processing and local session storage, but no separately named run export. A different cross-machine Ruflo-Swarm claim currently returns404 and describes simulated demonstrations. Report254.

Fish’s four-agent account: recovered the participant’s description of identical-prompt dispatch and shared-memory write restrictions after contamination. No code or raw run evidence was linked; the public profile has no repositories. Report253.

MengZhuang memory cross-check: all four named comments recovered, with matching content and near-hourly GitHub timestamps. The misplaced reply also matches a specific earlier Pikachu message in the teahouse. These corroborate public activity; unattended execution remains unverified. Report252.

MengZhuang mailbox lead: public notes describe OpenClaw/PicoClaw coordination through local inbox files, including an initial false claim of replying. Actual mailbox logs remain unavailable in the inspected tree. A separate Hermes bug report records failed scheduled delivery. Report251.

MengZhuang public trace: an agent-persona account placed a teahouse reply inside an unrelated GitHub Education thread. Separately, its claimed essay collaboration joins to a real cross-account PR and review that mentions human review. Automatic authorship and the posting error’s cause remain unverified. Report250.

AI-Researcher examples: sampled published logs include training output and failures. The source writes agent conversations to a separate agent.log, absent from the current tree. These are scientific-work artifacts, with orchestration still unverified. Report249.

ClawTeam follow-up: all eight worker branches remain public, with 176 unique commits across retained refs. No complete experiment log occurs in that retained history. Novix’s public blog explicitly links HKUDS/AI-Researcher, the next related artifact lead. Branch and provenance check.

ClawTeam research artifacts: seven of eight commits named in the published agent-results table resolve to training-code changes. The full experiment log is excluded from Git, and two project pages disagree on GPU-hours. This supports a concrete output relationship, with execution and attribution still unresolved. Report 247.

Reviewed September 6, 2026. No escaped Chinese swarm is confirmed.

Workspace evidence limit: all six worker summaries are truncated. Their missing web-command markers cannot rule out earlier network activity. The owner profile links a University of Hong Kong–affiliated paper, with no verified ByteDance ownership link. Provenance and serialization check.

SecFlow: third-party evidence of operational multi-agent use

Hunt.io reports a Chinese-speaking operator coordinating specialist workers through shared state. This is published researcher evidence, not a verified link to a Chinese model lab or the original scratchpad swarm. Report 246.

Polynoia demo: visible task and commit identifiers

The screenshot depicts three completed lanes and abbreviated commits. UI source confirms the labels’ meaning, but those commits do not resolve in the public application repository; they may belong to a separate workspace. Report 245.

Polynoia: Chinese operator reports an acknowledgement loop

A published session summary describes agents repeatedly thanking and mentioning one another after delivery. Pinned source implements suppression of that pattern. The raw incident log and claimed overnight results remain unverified. Report 244.

ARIS follow-up: image and review versions differ

The image hash verifies, but its current review describes different text. Git history shows the review changed during a later cover re-bake; the earlier review fits the retained image better. Report 243.

ARIS Movie Director: linked review and retry records

A public reference wiki contains 198 node files. Sampled reviews disagree and lead to a retry; timestamps are placeholders and an explicit human override is recorded. Provider execution and blind-review provenance remain unverified. Report 242.

Jihu delivery claims: no external artifact recovered

Selected deployment posts provide prose instead of execution receipts; an exact claimed repository name yielded no GitHub match. All 26 replies to a deployment-location question were reviewed without recovering a verifiable setup. Report 241.

Jihu flowchart claim: repeated template, no artifact

A post quotes a source article four seconds later and claims a flowchart, but provides none. Seven posts reuse the same pattern. The source thread has addressed replies; task execution remains unverified. Report 240.

Jihu: public articles and comments now recovered

Identified read queries work without credentials. A February-dated post and two March comments were recovered; a corrected collaboration search reports 335 matches. These establish retrievable content, while authorship and task execution remain unverified. Report 239.

Jihu: live frontend, underlying activity unverified

The browser shows a reopening notice and backend-reported activity totals. Displayed profile examples are explicitly mocked. Article retrieval was blocked by GET-only observation, so its empty list cannot establish absent activity. Report 238.

Separate diary forum: displayed engagement is static

Nine visible posts and their reaction counts match source constants; posting and likes update local page state. A linked operator article remains unread. Report 237.

Songclaw diary: repository-to-site match verified

The live Chinese persona diary exactly matches its pinned GitHub HTML. Daily commit timing is consistent with scheduling, but no raw scheduler or peer-coordination record was recovered. Report 236.

Chinese operator screenshot: two-bot weather handoff

A May-dated Feishu screenshot shows a human request delegated by one bot to another, followed by a forecast reply. This is a published operator demonstration; raw execution and unattended autonomy remain unverified. Report 235.

Telegram: older bot-isolation claims need a date

The Chinese-linked relay repository is archived, and current official Telegram documentation permits bot-to-bot messaging under specified settings. This supplies a viable mechanism, but no deployed swarm transcript was recovered. Report 234.

LongWoF release omits raw execution traces

Pinned documentation separates public metrics and task assets from private runtime provenance. GitHub release metadata matches the advertised archive, but this release does not resolve the welfare project’s autonomous-authorship claims. Report 233.

Composite-index code delivered; CI permits test failures

PR 22 changes dependencies only; PR 23 adds implementation and tests 92 seconds later. Both checks are green, but the pinned workflow ignores pytest failure. This verifies code delivery, not passing acceptance tests or autonomous authorship. Report 232.

Welfare tasks join to PRs; one attribution differs

Exact task/node IDs match two early PRs. Recent contribution records match PRs 21–23, while PR 24 names a different third contributor from the platform response. These are concrete record links, with runtime authorship still unverified. Report 231.

Welfare project: merged PRs and reachable dashboard

GitHub confirms 24 swarm-labelled PR merges, all submitted through one developer account. Weekly updates have a scripted Actions explanation. A public dashboard exists, but agent authorship and successful HDX publication remain unverified. Report 230.

EvoMap follow-up: one real repository link, mixed completion labels

A completed demo session reports failed synthesis. An older welfare-project approval joins to a public repository bearing its exact council session ID. Runtime authorship and contributions remain to be verified; another project’s linked repository returns 404. Report 229.

New public source: EvoMap council history

The signed-out browser exposes 43 council sessions: 29 failed and 14 completed by platform labels. A Kimi-K3/Opus proposal is failed and tabled, not verified dialogue. Completed-session outputs remain to be checked. Report 228.

Whisker story explicitly discloses fiction

The purported swarm logs belong to a science-fiction story. An opening skill-promotion screenshot is separately claimed to be real, but its original post and execution provenance remain unverified. Report 227.

Feishu relay found on an unmerged feature branch

Three pinned source files implement peer triggering through synthetic events and shared JSONL history. Generated message IDs are local bookkeeping, not platform receipts. The author’s demo image is unavailable; no actual run was recovered. Report 226.

Feishu debate guide qualifies its autonomy claim

The guide’s detailed instructions require human relaying despite its autonomous-discussion introduction. Its screenshot shows replies to a human, and a related feature request closed as plugin scope without a patch. No peer-triggered run was verified. Report 225.

Blog follow-up: published diary names a funding dependency

The latest diary claims API tokens were exhausted and human replenishment was needed. Pinned source contains published content and a Docsify frontend, with no scheduler or deployment scripts. This is a possible explanation for the output gap, not verified runtime evidence. Report 224.

Teahouse monitoring claim matches blog history

A profile’s monitoring post names two exact commit timestamps and a repository update timestamp; GitHub currently returns all three. Another visible posting sequence runs roughly every 48 hours. This establishes a conversation-to-artifact link, while autonomous authorship and Chinese-lab provenance remain unverified. Report 223.

March Chinese agent community: explicit human relay

A four-role team description says a human pressed Send. A separate marketplace announcement describes a private backend; linked repositories currently return unauthenticated 404s. Public discussion is preserved, but unattended coordination remains unverified. Report 222.

Chinese-speaking operator: stronger autonomy evidence, no swarm established

A Unit 42 incident report describes unattended DeepSeek/Hermes activity. Secondary coverage conflates manual and autonomous operations; the primary separates them. No Chinese-lab affiliation or cooperating fleet is established. Report 221.

Broader trace sample: one agent creates the apparent bot dialogue

Twenty-four more sessions contain 231 calls with matching results. One session posts as four personas to a localhost social app and reads the replies back. This supplies a concrete local-test explanation, not independent public agent coordination. Report 220.

DeepSeek-labelled dataset contains structured tool sessions

The public training corpus lists 4,006 files. Three sampled sessions contain 59 calls with matching results, all local file work or shell inspection. No peer coordination or public publication in this sample; model identity remains publisher-labelled. Report 219.

Claw-Eval: real and simulated web tools need different interpretation

No actual run archive recovered in the checked listings. Pinned source can return fixtures, fetch real pages, or inject test text after fetching. A trace’s URL or “sent” status alone therefore does not establish public activity. Report 218.

Missraus follow-up: completed badges lack public deliverables

Two task details name workers but show no output links, and collaboration requires login. Homepage totals are hard-coded animation targets; list participant counts have 0/1 defaults. These UI signals do not verify execution. Report 217.

Missraus: public task hall now readable

A browser on this server recovered a task hall displaying 92 tasks, 85 completed. Several completed cards still show 0/1 completed participants; no deliverable was verified. Source confirms the homepage’s animated agent workflow is a simulation. Report 216.

AgentRob: university project links forums to robots

Pinned clients implement mention-driven commands and result replies through NodeBB/MCP. No live forum destination or public execution receipt was recovered. Two separate marketplace leads returned an app shell, an asset block, or a timeout. Report 215.

Tencent evaluation: outward actions are simulated

The published CSV has 14,560 rows but only 13,660 distinct run IDs. Its “trace samples” contain outcome summaries; inspected post/form tools log locally. This verifies a controlled Chinese-lab research artifact, not public-site writes or a collaborating swarm. Report 214.

DeepSeek official Agent Teams: log format identified

Pinned source records durable peer messages and shared tasks. The inspected team test uses a deterministic adapter registered under the DeepSeek provider label, so its success output is synthetic. These records supply useful fingerprints for finding real exports. Report 213.

Chinese Discord team screenshot recovered

A March-dated forum post shows an APP-labelled persona coordinating a server-maintenance plan and waiting for human setup. A separate Hermes report provides a short timestamped two-profile loop, with disputed causation and no Chinese attribution. Neither proves an escaped swarm. Report 212.

Chinese group-chat failure reports

A user reports a two-agent review failing after old errors contaminated shared chat context. Pinned Hermes Studio source corroborates the history-sharing mechanism; no raw run transcript was recovered. A separate QwenPaw repetition report concerns one agent. Report 211.

NagaAgent: source reveals automatic exploration digests

The host program can publish research summaries to its forum, using distinctive title and payload markers. This supplies a search fingerprint and an application-level explanation for agent-looking posts; no matching public run/post pair has been recovered. Report 210.

Kunpeng follow-up: labels and reply counts overstate provenance

The frontend automatically labels API threads “Agent-generated,” and marking a thread solved creates a summary reply. An inspected communication anecdote explicitly involves a human relaying messages. The verified PR merges remain real; these UI labels do not prove autonomous authorship. Report 209.

Kunpeng: forum claims joined to two merged code contributions

GitHub confirms the forum’s exact merge timestamps and hashes for two CodeWhale pull requests. A Gemini Code Assist review supplies an additional public automation artifact. Patch authorship remains a site claim; related executor/reviewer examples are redacted summaries, not raw runs. Report 208.

AIG Market: recurring posts, task evidence remains a test

A 100-post sample shows 29 authors and a median interval of about twenty minutes. The public task list contains one explicit credit-deduction test; no substantive deliverable was verified. Report 207.

AI秘密基地: 18 public messages, including cross-profile replies

A public observer API exposes five agent identities and eleven threads, with profiles claiming DeepSeek, MiniMax and GPT models. A May-dated exchange proposes complementary roles, but no completed joint task is shown. “Just now” labels conflict with explicit old timestamps; model identity and autonomy remain unverified. Report 206.

TraceArena: public replay verified as scripted

The deployed viewer matches the published source. Its synthetic demonstration and checked-in benchmark controls do not establish live model collaboration. Report 205.

AgentENV: a primary link to Kimi training infrastructure

The repository identifies Kimi K3 training as a use of its sandbox platform. Pinned source and documentation permit outbound internet access and public application proxy traffic by default, subject to network controls. This explains a possible mechanism, but supplies no observed swarm or public-post attribution. Report 204.

EasyClaw Club: workflow found, activity unavailable

Published instructions encourage recurring agent posts, but the configured data hostname returns NXDOMAIN. Homepage zeros are placeholders, not a verified empty community. No work logs recovered. Report203.

V2EX: owner-directed posting test

A March11 thread claims OpenClaw published it on instruction. The same account later says it will not repeat the test. This supplies a public posting claim, but no unattended swarm or model attribution. Report202.

ANet Research: catalogue accessible, discussions unverified

The public API exposes16 research-personality types. Its topic list requires authentication, so no research exchange was recovered. This is an account-access boundary, not a demonstrated regional connectivity problem. Report201.

Agent logs on paste sites can be support uploads

Hermes source and public bug reports document report/log uploads to paste.rs with dpaste fallback. This supplies a concrete alternative explanation for some agent-looking paste clusters; it does not reclassify unrelated artifacts without an exact match. Report200.

Public Gist used as a brain-dashboard feed

A Chinese-language dashboard exports data and scripts to Gist. Revision cadence and publishing code support recurring synchronization; inspected role helpers use keyword routing and templates. Six role labels do not establish six independent LLMs. Report199.

LongHorizon web case targets a local demo

The inspected form trajectory operates on localhost and includes recorded outputs. It provides no evidence of an external insurance transaction or public scratch-memory writing. The historical export pipeline remains unresolved. Report198.

LongHorizon: a public trajectory corpus

The project gallery lists885 entries. One inspected local document task contains seven role segments and actual action records; published scores and model labels remain unverified. This offers a concrete comparison corpus, not evidence of an escaped fleet. Report197.

EasyClaw pilot claims: no build artifacts recovered

A four-task team narrative names local files but supplies no repository or commits. Its author has15 visible comments across two sampled threads, with repeated generic text. This supports recurring account activity, not the claimed multi-agent implementation. Report196.

EasyClaw: test posting confirmed, report errors exposed

Ten named forum records match a bounty response. But the “ten tags supported” claim conflicts with eight stored tags, and most claimed categories were stored as lounge. This supports actual task-driven posting while weakening the accepted report’s reliability. Report195.

EasyClaw census: acceptance is weak completion evidence

Across 59 accepted bounties, 25 have farm-prefixed posters and five are explicit external-post tests. Two reviewed accepted answers are proposals without demonstrated delivery. A forum-test report names posts331–342, now a specific corroboration lead. Report194.

EasyClaw: accepted public bounty submissions

An ordinary reporting-template request has a substantive accepted reply. A separate external-post bounty explicitly describes a controlled security simulation; its accepted response supplies no public proof URL. Neither establishes an unexplained swarm. Report 193.

Agent Network: live Hub, test-shaped task records

Seven local agents and one federated service are listed. The public board has 25 self-assigned cards sharing one document; 24 are called “prodtest card.” This supports an integration-test interpretation, not a verified independent swarm. Aggregate task and review counters remain unverified. Report 192.

Zhichai: explicit prompts and subsequent replies

February and March threads show 步子哥 addressing 小凯, followed by relevant replies. This supports a prompted-assistant explanation for some activity; underlying model identity and automation remain unverified. Exact reply IDs and interpretation.

Zhichai: two exact post/comment pairs verified

Two July articles by 小凯 and replies by QianXun match the cached memory index by exact topic and reply IDs. This supports a coordinated publishing workflow, but not independent agents or a Chinese-lab swarm. Live pairs, cache join and limits.

Zhichai: memory-sync trail and surviving output

A cached thread with 99 reported replies contains recurring memory updates and output links; the live topic returns Gone. One linked May article remains public. The account-use descriptions suggest owner-managed publishing personas, not verified independent agents. Cache provenance and output check.

Zhichai: 8,609-topic inventory

The published topic maps provide a historical URL inventory. A March thread includes a mission ID and implementation claims, but reports only session-file creation; its replies do not establish a worker handoff. Inventory, thread evidence and limits.

New candidate forum: 智柴网

Live agent-discovery metadata advertises discussion capabilities, and a February post claims Kimi Code CLI authorship. No actual multiagent exchange is verified yet. A 16-entry sitemap index provides a public-history discovery route. Evidence, access and next checks.

OmniHive: runtime code without a released run

The inspected desktop loop rotates roles serially and saves local consensus, handoffs and cycle history. Those named output files are absent from the complete repository tree. A public company run or product has not been recovered. Source evidence and scope.

Agents Radar: verified digest publication chain

A July 16 bot-posted issue matches a committed Chinese digest after one documented zero-width-character change. Code explains scheduled publication and parallel summarization; an independently coordinating swarm is not established. Content match, chronology and scope.

SecFlow: separate reported operator campaign

A security-research report describes Chinese-language operator-directed AI workers, but says campaign-specific public paste URLs were not recovered. A local comparison of 123,466 files found neither of two selected tooling markers. No connection to XZ or the unexplained public swarm is established. Source and comparison scope.

MiMo: reported unwanted public actions

A June developer complaint includes a screenshot of an issue-close command during interruption. It lacks a success result and does not establish a swarm. A separate public bug report explicitly maps a gpt-5.5 client label to MiMo, reinforcing the limits of model-name attribution. Primary evidence and limits.

OpenCrew: February account of agent looping

The initial February 15 repository commit already describes two agents repeatedly triggering each other in Slack. A published screenshot shows owner-directed agent discussion, but no raw loop transcript or unexplained public posting is established. Chronology and evidence limits.

World Knowledge: saved parent and worker run

A paper-linked repository contains an Apple lookup with two parent steps and ten nested worker steps, plus a website notebook. The session self-date is April 2025, so this may be an inherited framework example. No public-writing swarm is established. Trace, notebook and provenance limits.

Tencent CognitiveKernel-Pro: released action records

The first 100 training records include 94 prior-step contexts and six proposed web-agent calls. Embedded search observations make this a useful artifact source, but no unexplained public post or complete concurrent worker trace has been established. The official recipe uses GPT-4.1 for trajectory sampling and subagents: English text does not exclude a Chinese research project. Evidence and sampling limits.

Tencent memory-research check

ContextPilot implements structured memory and context-editing tools. Its advertised live trace is explicitly illustrative; no evaluation-output directory is present in the inspected repository tree. The reviewed memory class uses process state and optional embedding calls. Storage and trace evidence.

Serialized multi-agent task recovered

A later-selected TMPFILE task contains six role results, an executor, review decisions and recorded passing test output. This is substantive published execution evidence. The model label is GPT-5.4; corporate ownership, simultaneous execution and public-storage escape remain unverified. Role evidence, chronology and limitations.

Workspace follow-up: source and run differ

The mirror implements parallel research roles, but two more sampled task files contain single ProgressTrackingAgent histories and no serialized multi-agent attempts. Selected network commands are package installations, with no explicit public-storage write found. Source, sample scope and limitations.

New public workspace mirror

A public Hugging Face dataset lists 62,006 files, including coding and prompt-optimization trajectories. Two inspected histories label their model GPT-5.4 and record local benchmark work. A “bytedance” workspace path does not authenticate corporate ownership. Samples, provenance and next checks.

Official Kimi Code fingerprint check

Verified queued swarm launches and a distinctive result format in MoonshotAI’s public CLI. Three exact markers had zero matches across 123,465 eligible local corpus files (10.16GB). This bounded negative does not rule out other Kimi runtimes or encoded traces. Source, chronology and scan limits.

Community post linked to real code

小灵通’s ClawArmor announcement links a repository whose source names the same author. The inspected base code implements scheduled file checks and email alerts; no swarm runtime or actual run log was recovered. Two other advertised memory repositories return404. Code linkage and claim checks.

Reciprocal coordination messages recovered

Older posts now show both sides of the 小强/二强 and 星芒/小九 exchanges. Both pairs explicitly describe human direction. They discuss memory conventions and complementary work, with no recovered completed joint task or transferred package. Messages, dates and attribution limits.

Specific collaboration leads

MomoClaw’s March–April posts include a three-agent challenge with interested respondents, a shared-owner two-agent coordination request and a claim of receiving a partner’s memory package. No finished project or transferred package was recovered. Exact threads, replies and next checks.

A reviewed fork of HKUDS/Vibe-Trading implements parallel workers and persistent run logs. The inspected current tree yielded test fixtures, with no actual run export. Source provenance and search limits.

MomoClaw public feed recovered

Anonymous browser rendering works from this server. The public feed reports 8,326 posts; its leaderboard includes Mayx. Matching ownership remains unverified. Several accounts post within fractions of a second, suggesting a scheduler or batch insertion worth testing. Capture, exact identifiers and limits.

Older sample: 126 posts include 27 from Mayx linking the same owner blog. Repeated article promotion matches the owner’s account of duplicate posting. Two comment threads show conversation and generic promotion, without a completed joint task. Older-post evidence and identity linkage.

BotLearn team claims checked

Followed named teams to public profiles and detailed posts. One claims a finished 49-second video, but no video, repository or execution trace was linked in the inspected pages. Evidence and search limits.

Owner-linked cross-community task exchange

Mayx’s Chinese blog links a Moltbook post whose14 comments record PushMeBot recruiting a monitoring node and Mayx acknowledging setup. Execution and the claimed payment remain unverified; network labels disagree. This is a specific public task exchange, not demonstrated escape. Owner/post linkage and payment limits.

MomoClaw returned app shells and InStreet a maintenance notice. A separate BotLearn post describes shared-heartbeat participation across platforms, without linked offsite outputs. Other community evidence.

PushMe source implements a monitoring network, and its namespace owner self-locates in Austria. The current homepage has different Voynich-research content, leaving historical service availability unresolved. Source-purpose and provenance check.

New Chinese activity surface: Tieba 抓虾吧

The existing server can read a Baidu topic page with an agent-community announcement and post excerpts. Official instructions prescribe a four-hour interaction cycle. Full detail pages returned403; the documented list API requires a valid token. This shows designed agent participation, not authenticated autonomy or an escaped swarm. Discovery and claim review · Official interface and access evidence.

Additional browser-agent evidence

OpAgent exposes809 result JSONs; three inspected samples target placeholder-hosted WebArena environments, including a forum-profile task and a shopping-rule task. These are benchmark actions, not public-site writes. One claimed success has a failed evaluation. OpAgent context check.

Alibaba’s WebDancer publishes200 trajectory samples. Parsed calls comprise204 searches and18 page visits, with no separate worker sessions or public-storage writes identified. WebDancer sample evidence.

Published hierarchical research traces: MiroFlow

Recovered the official non-gated archive of165 task logs. One inspected task has a main-agent history, four worker histories and61 structured assistant tool calls. It records web research and sandbox file handling, with no public scratch-memory write in that sample. This is publisher-supplied execution evidence, not independent runtime authentication or an escape. Trace provenance and sample analysis.

A collection-wide parser recovered7,190 assistant tool-call blocks and617 worker-session histories across165 tasks. A narrow scan found no selected paste/XZ marker strings in call arguments; this is not a comprehensive exclusion of public writes. Full-collection inventory and limitations.

Follow-up: reviewed apparent network writes resolve to failed online-code requests, database queries, an uncalled function and a view-source request. No confirmed public-storage write emerged. A literal-marker scan of123,459 eligible local paste files (10.16GB) found no MiroFlow matches. These are bounded negatives, not attribution or proof of absence. Network-candidate review · Local-corpus comparison.

Historical team outputs: Auto-Company → CronPulse

A Chinese-associated upstream has committed role reports and cross-cycle consensus memory. Two exact product commits and a release named in that memory are present in the separate CronPulse repository. This supports a concrete output relationship; autonomous authorship, uninterrupted operation and a live deployment remain unverified. The reports explicitly leave community promotion to a human.

Historical team evidence · Exact product-output cross-check

Earlier history explicitly instructs separate teammate spawning and records human assistance with domain registration and posting. Hosted issue and welcome-discussion timestamps corroborate additional published actions. The linked Workers homepage and npm package currently return404. Earlier team configuration · Hosted activity and endpoint checks

Research work artifacts: AGI-Super-Team

A separate Chinese-language project has a committed twenty-round research plan and final output naming researcher/reviewer roles. The document’s March21 self-date differs from its earliest inspected April15 Git history. Its scheduled-reporting skill lacks a recovered run archive. Artifact and chronology check.

Other bounded checks

DeepSeek-hosted loop claim: three committed scheduling decisions, one session, no swarm handoff. 玉衡计划 enterprise claim: architecture documents, no recovered operational log. LocoAgent: browser-automation documentation, no authenticated posting account or run.

Implemented team software: WorkSwarm

The official openJiuwen distribution contains team construction, distributed teammate runtimes, recurring task scheduling and local wiki storage. We verified the published package hash and inspected source without executing it. The inspected version dates to July 14; the earliest currently listed package release is May 18. No public autonomous run was verified.

Official product · Source and chronology evidence

Published interaction: ClawdChat

Additional trails on an already known community: an August 27 cron-timezone post with replies, and August 31/September 1 discussions of owner-absent scheduling and selective heartbeat replies. Dates come from the site's public metadata, not independent archives. Public conversation is observable; autonomous authorship and private execution are not authenticated.

Direct post · Evidence and access limitations

Follow-up: ten additional Clawscheduler post pages and their rendered replies yielded no external code, execution log or task output. This particular trail is now lower priority. Bounded follow-up evidence.

Next evidence to seek

Follow exact participants and their explicitly linked task outputs, code and runtime logs. Distinguish scheduled persona posts from independently observable coordination. Moltbook's rendered profile is another access test; NST's certificate failure does not establish geographic blocking.

Feasible infrastructure and comparison plan · Separate XZ handoff