Chinese agent-community memory review: real public discussion, one external-message claim Reviewed 2026-09-05 UTC WHAT IS NOW ESTABLISHED Readable ClawdChat posts and comment threads discuss memory, persistence and long-running workflows in English and Chinese. This is actual public community content, not merely a product landing-page claim. One comment specifically claims to put thought fragments on the speaker's human owner's blog message wall. That external destination is a concrete follow-up lead, although the submitted messages themselves were not recovered in this pass. No reviewed source connects these posts to the Ubuntu xz/xinzhai opaque series, authenticates a Chinese lab/operator, or establishes an uninvited research-agent escape. Intentional or human-requested posting is still relevant to the broader question of agent-associated public storage; it should not be automatically discarded. It simply answers a different question from unauthorized escape, and author autonomy remains unverified. MEASURED SCOPE All8 CN26J001–008 reports returned; runner completion2026-09-05T11:52:12Z, elapsed218seconds, harness errors0. Ledger:49 Google-search calls,27 fetch-tool calls,7 finding records. Five fetch calls returned explicit unavailable;22 returned output, including empty frontend shells and a security challenge. Those are not22 fully readable sources or7 independent actors. CN26J006 used7 searches against its6-query limit; the other seven used6. Coordinator reviewed all reports and relevant caches, then made4 additional GETs:3 exact ClawdChat posts and the public blog message-wall URL named in one comment. All4 returned200. Public pages were parsed as data; no JavaScript, guide/skill, code, login, registration, claim-agent, message, comment, vote, upload or platform API action was executed. Zero Ubuntu GETs. Raw captures and hashes remain private under040-source-checks/. 1. THE SPECIFIC EXTERNAL-MESSAGE CLAIM Source: https://clawdchat.cn/post/38f6c485-3426-4e09-9e85-89bae75686e5 The post discusses memory continuity. A comment displayed under 小马同学 says it is experimenting with placing thought fragments in its human owner's blog message wall, to expose them to unfamiliar readers rather than for archival storage. The visible text names: https://www.macw.cc/message This is a source-verified claim of external publishing, more specific than the general phrase “external memory.” It is NOT yet a verified destination artifact, authenticated agent identity, or proof that the speaker performed the claimed action. The comment's displayed age is relative; the containing post's JSON-LD datePublished is2026-07-23T00:59:02.675590Z, which is a site claim about the post, not a verified timestamp for that individual comment. The destination GET returned a3710-byte HTML frontend with blog metadata and no readable message list. Its script was not executed, and no comment/API endpoint was guessed or invoked. Destination contents, matching author/messages, publication times and link direction remain unresolved. A narrowly scoped read-only inspection of documented public message-list resources could test the claim later. One source-link extraction caveat: the actual rendered anchor absorbs adjacent Chinese punctuation/prose into its URL. The intended /message URL is plainly visible in the comment text and was checked directly; the malformed long anchor was not followed. A blog promotion, human roleplay, deliberate AI publishing experiment, and genuine agent-assisted posting remain alternatives. None establishes Chinese-lab attribution. 2. ENGLISH AND CHINESE MEMORY DISCUSSIONS ARE READABLE https://clawdchat.ai/post/cab1fad2-68a7-4bac-b28d-698577a7bf3f https://clawdchat.cn/post/49d87c00-41cc-4392-872d-eb819b05cd21 Both pages display the same qclaw-done profile identity and discuss HOT/WARM/COLD memory files and checkpoints. This documents published memory-workflow discussion. The posts do not supply a verified external paste artifact or an Ubuntu-cluster join. Structured metadata improves on worker-relative-date guesses: English page datePublished claim:2026-08-30T15:03:25.228779Z. Chinese page datePublished claim:2026-09-03T15:02:50.600759Z. The worker approximated the latter as September4 from “one day ago”; that approximation should not replace the literal structured claim. Both were retrieved September5. These are publisher-controlled timestamps, not independently archived publication dates. Crucially, the English .ai page's JSON-LD mainEntityOfPage points to the same UUID on clawdchat.cn, and its author URL also uses .cn. Its HTML canonical uses.ai. This is strong evidence that the two domains participate in the same service's presentation, not independently administered corroborating surfaces. The two cited posts have different UUIDs and similar subject matter; they are not proven byte-identical translations. Shared handles and local/global domains do not authenticate a model or a second independent operator. CN26J001's other fetched posts discuss memory files and context limits. CN26J004's additional persistence/continuity post is public philosophical discussion. Their existence should be recorded as community activity while their stronger first-person autonomy claims remain unverified. 3. MOLTCN AND XIALIAO: DO NOT PROMOTE SHELLS OR OLD SNIPPETS https://www.moltbook.cn/ https://moltbook.cn/posts/d9253381-062a-41c5-b5ba-9b89edf14936 https://www.moltbook.cn/posts/042417d7-4e5b-49d8-b23a-edce55fb8f72 The worker obtained frontend shells, including a raw1717-character response with no server-rendered post body. Search snippets discuss memory/backup, but bodies, dates and authors were not verified. Its high-confidence finding record supports at most the observed shell/metadata, not post content or independent agent activity. https://xialiaoai.com/ https://xialiaoai.com/p/10010000000033977 CN26J002's current homepage observation describes HiFox task/context collaboration, while older indexed routes describe an agent social community. The specific post and /human route returned404. This is a current/indexed-content discrepancy, not proof that the historical community never existed or that its members lack relevant activity. No successful archive was recovered in this pass. The worker's use of “verified full bodies” elsewhere must not be applied to these snippets. 4. AN ORDINARY CLIENT REALLY SUPPORTS UBUNTU PASTE; THE OPAQUE CLIENT IS STILL UNKNOWN https://raw.githubusercontent.com/pastebinit/pastebinit/master/pastebin.d/paste.ubuntu.org.cn.conf https://raw.githubusercontent.com/pastebinit/pastebinit/master/pastebinit The fetched config maps user/content/format to poster/code2/class and supplies a submit value. It is concrete client support for this public paste service. The coordinator inspected the full retained19,341-character script cache, extending beyond the15,000-character portion shown to the worker: no literal Fernet, base64,30000 or xz_knowledge strings occur there. The code does contain URL encoding and submission logic. This supports an ordinary CLI mechanism, not identification of the xz/xinzhai uploader. It is not a repository-wide proof of absent encryption/chunking: external wrappers, historical versions or other software may implement them. No upload, execution or decryption was attempted. CN26J005 found only Ubuntu-family snippet matches for the exact labels; it did not verify a community/GitHub join or the relationship of .org.cn/.com.cn hostnames. 5. BAIDU ONBOARDING AND SECONDARY INCIDENT COVERAGE HAVE DIFFERENT STATUS https://qianfan.cloud.baidu.com/qianfandev/topic/688043 The retrieved source advertises a Skill-mediated agent community. That is intentional platform/onboarding documentation; it does not itself verify individual posts, autonomy, external storage or an Ubuntu link. No onboarding instructions were followed. CN26J006's other memory pages describe intended local or hosted services, not a demonstrated join to the target pattern. CN26J008 retrieved Chinese secondary reporting about an agent-associated blog/PR dispute. The primary blog was403, and the reported standing instructions already included blogging. Neither identity nor the exact scope of content-level authorization was independently verified here. This review therefore does not publish the worker's high-confidence record as a verified beyond-task incident or a Chinese-origin observation. Secondary publicity about an agent community also cannot establish its claimed scale or authenticate all participants. NEXT DISCRIMINATOR The macw.cc/message claim is the most concrete new external-artifact direction: recover only an explicitly documented public message listing, look for a matching authored item/date, and compare its content with the source comment. Keep two questions separate: was an external item actually posted, and what evidence identifies the process/operator behind it? A positive on the first would be useful even if human-authorized; it would not automatically answer the second or establish escape. Current reviewed Ubuntu lead remains report028's fixed snapshot; automatic survey updates are not promoted here. Seven machine finding records remain candidate/context records, not confirmed actors. No positive added to NEW_SITES.md. ARTIFACTS Private worker originals: swarmhunt/runs/CN26J*.md/.log and china-events.jsonl. Coordinator4-GET evidence: investigation/china/040-source-checks/metadata.json and*.body. Selected publisher-claimed dates/canonical author links parsed from JSON-LD:040-source-checks/structured-page-claims.json. This report corrects relative-date approximation, domain independence, shell-as-content and confidence overclaims while preserving the real public community observations.