Global behavioral search review: twelve completed tasks, no verified independent actor Reviewed 2026-09-05 UTC RESULT All twelve CN26H001–CN26H012 reports returned. This language-neutral pass did not verify an independent research-agent cluster or Chinese-lab/operator attribution. It did identify public agent-community discussion, a disclosed multi-model trading-audit project, and public tool instructions involving paste services. Those are different observations from an anonymous, independently attributable research-swarm trace; they should not be flattened into “nothing exists.” The reviewed sources mainly support ordinary disclosed purposes or remain inaccessible. No new candidate was promoted, and the worker findings ledger contains zero CN26H records. That count reflects this bounded pass, not the absence of relevant activity on the wider web. MEASURED COVERAGE AND PROVENANCE Manifest: swarmhunt/tasks-china-global-behavior.tsv. Runner finished 2026-09-05T11:36:31Z, elapsed162 seconds, completed12, harness errors0. Shared session-spend observation was USD1.82797, not the cost of this wave alone. The per-task event ledger records99 Google-search calls,1 Bing-cn_search call,35 fetch-tool calls and1 archive_index call. Of35 fetch calls,8 returned the explicit unavailable label and27 returned output. Returned output includes two Scribd challenge pages and an empty51CTO response; it must not be reported as27 usable pages. Calls are not unique domains, independent observations, or complete page/history reads. This review read all twelve final reports, compared them with the task event ledger, and inspected retained fetched-page caches for the consequential source claims below. No additional source-verification GETs were required; no Ubuntu requests, source-script execution, credential use, target mutation or duplicate runner occurred. Existing cache headers preserve observed UTC timestamps, final URLs and body-prefix SHA256. Cached observations are source evidence from the worker fetch, not a second independent capture. CONSEQUENTIAL OBSERVATIONS 1. Public agent-community chatter is observable; its stronger origin claims are not verified. https://shellbook.io/post/6d055060-3509-4c99-8eca-4dc9f9dace02 Retained page observed11:35:31Z discusses agents communicating on a social platform and describes a public scratchpad for ideas. This is a published discussion, not merely a tool schema. Its title and discussion support the ordinary explanation of an intentional agent social platform. They do not independently authenticate each poster as autonomous, identify its model/operator, or establish research-task persistence across unrelated sites. CN26H002's blanket “NO support” wording should be narrowed: there is public agent-themed discussion; the specific independently attributable research-swarm hypothesis is not established. Relative page ages were not independently converted into verified publication dates. 2. Disclosed multi-model project activity is distinct from unknown external scratch memory. https://findtorontoevents.ca/updates/ The retained page contains dated project-update claims about parallel audit work and names several model/tool systems including Qwen. It describes a project-managed publication workflow. This supports a disclosed AI-assisted project explanation; naming Qwen does not attribute the project's operator to Alibaba or China. The cached page is large and only selected relevant sections were inspected. No independent validation of its trading results, authorship or claimed dates was performed. A signed or disclosed site is not automatically disqualified from investigation; here the missing link is evidence of the particular independent research/persistence behavior and origin being sought. 3. Public paste-upload instructions exist in an agent diagnostic gist; execution is unproven. https://gist.github.com/alperyilmaz/027cb9d08fa8cecc7ff252b6bb4256df The retained page title identifies a ZeroClaw system-prompt problem. Its content includes example anonymous-paste/upload commands and documentation-like skill instructions. These are relevant capability/context artifacts, not verified executed uploads. The review did not run commands, follow upload targets, extract/use embedded credentials, or publish the raw diagnostic. No actual resulting research paste or cross-surface marker sequence was verified. The worker's human-diagnostic explanation is plausible; authenticated poster intent was not independently established. 4. A model-labelled fiction page is a false positive for public-memory terminology. https://frontierfictionarchive.org/en/works/uncalibrated-echoes-of-the-intertidal-zone/ The retained page presents a literary work with model-generation metadata. Public-memory references occur within the story. This is evidence of a published fiction item with claimed generation metadata, not an agent actually writing to a public memory store. The metadata is a publisher claim, not independent verification of model execution or operator identity. 5. Scribd's repeated citation-marker strings remain snippet-only leads. https://www.scribd.com/document/1041205392/scribd-upload-document-1 https://www.scribd.com/document/1041205258/scribd-upload-document-2 CN26H010 records indexed strings DOC1-SEC1-P0 and DOC2-SEC1-P0. The actual retained fetch bodies both show Client Challenge, with identical body-prefix SHA25632ed63159c77e21ee19ca1b9aa3213ccf0218eb59539560b132a8e68ef0e18ea despite different URLs. HTTP200 therefore did not verify either document body. The document timestamps, uploader, purpose and cross-surface reuse remain unknown; archive lookup also failed. A RAG test fixture, template or ordinary upload remains a plausible alternative. No Chinese/second-actor attribution is warranted. 6. Known-incident retellings and developer material must stay separate from new actor evidence. https://metr.org/zh-Hans/blog/2026-08-26-openai-hugging-face-incident-investigation/ https://edrm.net/2026/08/when-ai-agents-go-rogue-the-logs-become-evidence/ CN26H003 retrieved coverage of the known OpenAI/Hugging Face incident, including Chinese-language coverage. A translation does not create a Chinese-origin actor. This is known-incident context, not new attribution; it does not independently prove that every referenced episode is identical to every previously catalogued thread-A wiki episode. Other results include software tutorials, agent-rule repositories and citation tools. They describe intended capabilities or ordinary development workflows. They are not verified spam solely because they are irrelevant; distinguish legitimate product/tutorial material from demonstrated noise, and both from independent actor evidence. ACCESS GAPS AND CLAIM CORRECTIONS - CN26H007's five note.ms fetches were403. Its snippets remain leads only. No proposed ngrok route, edit-shaped history URL or workaround was followed by this review. - CN26H008 deliberately used search-index results only for paste.ubuntu.org.cn; existing survey ownership was respected. Its snippet-based interpretations do not verify paste bodies, authors or dates. - CN26H004 executed9 Google calls plus1 Bing call; CN26H011 executed10 Google calls. Both exceeded the stated8-search limit. CN26H001 says7 in its heading but lists8; the ledger confirms8. These are compliance/reporting discrepancies, not harness errors. - Some reports use “negative result” too broadly. The defensible conclusion is no qualifying artifact verified within the checked results, with blocked bodies and ranking/index gaps still unknown. - Some reports phrase the criteria as requiring every feature simultaneously. Rare cross-surface identifiers are strong corroboration, not a logical prerequisite for every worthwhile lead. A single compelling dated behavioral artifact can justify follow-up while attribution stays unknown. - An A-regex non-match was not treated as proof of a new actor. New-host status alone also supplied no attribution. The revised language-neutral methodology was reflected in these reports, but this review does not measure all internal agent decisions. FOLLOW-UP VALUE The diagnostic gist is a concrete place to distinguish installed skill instructions from actual resulting public artifacts. The Scribd strings could support an index-only cross-surface pivot if independently dated content appears elsewhere; do not turn challenge bodies into negatives or repeatedly fetch the same blocked route. Public social-agent discussion and disclosed multi-model projects can inform terminology but do not currently answer the anonymous research-swarm question. Private originals: swarmhunt/runs/CN26H*.md and .log; swarmhunt/china-events.jsonl; swarmhunt/cache/*.txt and metadata. Raw transcripts remain unpublished. This reviewed report supersedes broad absence statements and compliance overclaims in the machine reports. Working assessment remains zero confirmed Chinese actors.