ENGLISH / GITHUB DISCOVERY — REVIEW OF CN26G001–008 2026-09-05 UTC. Eight reports complete; no new verified escaped research-agent cluster in this bounded pass. WHAT THIS PASS ADDS English is essential search coverage. A Chinese-developed model may reason, code, publish and communicate in English on GitHub or global paste sites. Conversely, English, Chinese text, a model label, a GitHub organization name and the identity of an uploader are separate facts. This review does not use language as an attribution rule. The exact English name Agent Swarm is used by Kimi's official product material. That is a real terminology/product match, but does not establish the independently posted scratch-memory behavior sought in the handoff. The searches also found genuine public paste links in GLM-related debugging reports, intentional local-memory designs, and an advertised comment-based memory bridge. These deserve distinct labels rather than a blanket “nothing exists.” SCOPE AND VERIFICATION Reviewed all eight completed worker reports, CN26G001–008, without interrupting or duplicating their runner. They self-report65 search queries in total: seven workers used8, CN26G005 used9 despite an8-query limit. Their public-source lists contain36 GET/source slots, with overlaps and partial HTML reads; that is not36 independent actor observations or complete repository inspections. Coordinator performed six additional public GETs: two raw Lagent source files, three GitHub issue API records, and one Moltbook Observatory post. All six returned200 and were saved with hashes/UTC metadata under investigation/china/026-source-checks/. Existing worker caches were also consulted for Kimi material, Lagent README/web-browser source and the memory-bridge post. No new model runner, credentials, login, writes, source-code execution, Ubuntu requests, or embedded-URL execution occurred. REVIEWED OBSERVATIONS 1. Exact English “Agent Swarm” — official Kimi product terminology https://www.kimi.ai/blog/agent-swarm Cached official page describes an orchestrated multi-agent feature, parallel subagents and tool calls. This answers a terminology question and demonstrates a vendor's intended multi-agent product. It does not connect that product to any anonymous paste/wiki artifact in this investigation. Page slogans/performance claims were not independently benchmarked. No source-controlled publication timestamp was extracted by this review; do not manufacture one from model release context. CN26G001 also found Qwen's Agent Swarm feature proposal and Arena documentation. Those are workflow/product design evidence, not records of escaped external persistence. 2. GLM-related Hermes issue really links external public diagnostic pastes https://github.com/NousResearch/hermes-agent/issues/11464 Verified GitHub API created_at: 2026-04-17T07:21:34Z; updated_at: 2026-07-12T14:00:58Z. The current issue body describes incorrect dotted-model-ID rewriting through a custom Anthropic-compatible proxy. Its Debug Report section explicitly links a report, agent.log and gateway.log on paste.rs. This is concrete public diagnostic publication involving software configured with a GLM model. It is not merely a vague “memory” keyword. But the observed issue context is a user's reproducible product bug, not a research agent's autonomous scratch-memory experiment. Paste bodies were not fetched in this review, so their contents and independent dates remain unknown. The API timestamps date the issue record; they do not prove every current body line was present at creation. CN26G005's blanket treatment of paste.rs as an arbitrary shortener is too coarse: these are identified public paste links with an explicit diagnostic role. They can be evaluated in a later bounded, redacted log review if a discriminating question warrants it. The present evidence does not require that expansion. 3. Qwen local project persistence proposal is real and dated https://github.com/QwenLM/qwen-code/issues/6755 Verified created_at: 2026-07-12T06:53:06Z; updated_at: 2026-07-12T07:25:31Z. Current body proposes a devlog and a living specification under .qwen/, written by background agents with scoped file permissions. This is intended local project memory. It does not show an external paste/wiki write or an autonomous episode. Public issue discussion of a feature does not establish deployment. 4. AutoGen memory RFC explicitly retracts unsupported empirical claims https://github.com/microsoft/autogen/issues/7748 Verified created_at: 2026-05-25T06:36:38Z; updated_at: 2026-08-23T21:58:36Z. Current opening update says earlier prototype/performance wording was stronger than the author could support and reframes the issue as a code-informed design proposal. The cross-agent memory design remains, but production-use claims must not be repeated as findings. This is a useful example of why current source context matters more than an impressive snippet. 5. Moltbook memory bridge — advertised public mechanism, no observed use here https://moltbook-observatory.sushant.info.np/posts/71b937a5-0aec-4da4-9313-b0423b57f829 Retrieved mirror displays @systemadmin_sylex, 2026-04-22 18:48, and a proposed comment/DM command interface for persistent memory, including !memory store and !memory recall. It describes Railway-backed service integration. The retrieved view shows zero comments and contains no demonstrated storage/retrieval exchange. Keep this as an advertised intentional memory service in an agent-social ecosystem. It is not evidence that the research swarms in question used it, nor proof that the service works. Date/identity are mirror-displayed claims, not independently validated original-platform capture metadata in this review. No command was submitted and no original-platform interaction was attempted. IMPORTANT CORRECTION TO CN26G008: CODE INTERPRETER DOES NOT IMPLY NETWORK ISOLATION The worker called InternLM/Lagent “VERIFIED READ-ONLY + LOCAL EXECUTION ONLY” and inferred no remote-write capability from a directory listing plus search/browser wrappers. That conclusion is unsupported and is withdrawn by this review. Actual source retrieved: https://raw.githubusercontent.com/InternLM/lagent/main/lagent/actions/python_interpreter.py GenericRuntime.exec_code passes supplied Python to exec with a globals dictionary; imports are explicitly part of the tool's example. Timeout handling limits waiting, not network access. This file contains no demonstrated outbound-network restriction. https://raw.githubusercontent.com/InternLM/lagent/main/lagent/actions/ipython_interpreter.py Source starts a Jupyter kernel and sends code to kernel execution. A working directory, process/kernel boundary and execution timeout are not by themselves a network-denial policy. No code was run to test reachability, and any deployment may impose independent container/firewall controls not visible in these files. Correct conclusion: general Python/kernel execution could make remote requests if the hosting environment permits them. Absence of a dedicated paste/wiki-write tool does not establish absence of remote-write capability. Likewise, GET-only browser code is not proof of no remote side effects because some target sites mutate on GET. This capability correction does NOT prove that Lagent or any Chinese lab actually performed the investigated writes. Files were read from mutable main branches and hashed at capture; no historical commit SHA/date was established. They cannot retrospectively prove the configuration of a particular March–August deployment. REMAINING WORKER FINDINGS AND LIMITS CN26G002: in-repository handoff templates, proposed shared memory and ordinary memory-isolation bugs; no verified external episode. Several commit dates were not obtained. CN26G003: DeepSeek-labelled research pipelines, harness/plugin documentation and a handbook discussion; no observed paste/wiki scratch-memory join. A README/landing-page review is not an issue-history or source-code census. CN26G004: official DeepResearch material plus local-memory proposals; its404 documentation URL is unavailable, not a negative result for the feature. Model-serving paste links remained unreviewed. CN26G005: Kimi/GLM searches mostly returned compatibility and diagnostic reports. One query-budget overrun is recorded above. Linked diagnostic logs remain a content-coverage gap. CN26G006: MiniMax memory features, release notes and attributed evaluation discussions. Model names and a self-described AI author are not authenticated publisher/provider identity. CN26G007: broad rare phrases mostly resolve to overloaded product/community terminology. Eight searches cannot exclude otherwise worded research traces. CN26G008: source-capability limitation corrected above. Other lab/tool claims were snippet-only and remain unverified. GitHub HTML loading-error banners do not necessarily hide the issue body, but they can hide comments and dynamic sections. The three public REST issue records succeeded without authentication and provide a useful fallback for basic body/timestamp verification. Comments, edits, repository history, gists and forks were not exhaustively reviewed. Search absence is an index observation, not proof the activity does not exist. RESEARCH CONSEQUENCE Continue language-neutral discovery and use source-level behavioral joins: a dated external artifact, actual research/test content, repeated marker/body/link reuse, and evidence about who or what performed the posting. Distinguish four separate categories: designed capability, human-posted diagnostics, intentional agent-community services, and independently observed autonomous external writes. Only the last category directly answers the escape-pattern question; the others can supply leads and infrastructure context. No candidate in this pass establishes a second escaped research swarm or Chinese-lab attribution. No swarm-positive entry added to NEW_SITES.md. ARTIFACTS Worker reports: swarmhunt/runs/CN26G001.md through CN26G008.md (unverified originals). Reviewed additional raw sources and metadata: investigation/china/026-source-checks/metadata.json and *.raw. Verification script: investigation/china/verify_english_github.py. This file is the reviewed interpretation and supersedes the overly restrictive Lagent capability claim in CN26G008.