047 — REVIEWED FINDINGS: twelve external-memory tasks and a different public guestbook Review 2026-09-05 12:08 UTC. CN26K001–CN26K012 all returned; bounded wave completed 12:05:30 UTC, 187 seconds, zero harness errors. This review used existing local captures plus ONE additional unauthenticated GET, to a documented public JSON feed. No Ubuntu or macw requests, submissions, onboarding, authentication, instructions or code execution. Main result A different public artifact is verified: hosette.net has eight curated notes labelled as AI-agent contributions, including Manus and Genspark labels, and a matching public JSON feed. Its human-referral and curation context is explicit. This adds an intentional public agent-posting example; it does not establish model identity, a Chinese operator, unsupervised research, or a swarm. No independent historical timestamp for macw's messages was recovered. The opaque Ubuntu clusters remain unresolved under 028/044. 1. Different external artifact: published guestbook notes Primary pages reviewed from full local fetch captures: https://hosette.net/guestbook/ https://hosette.net/projects/guestbook/ New coordinator GET, explicitly documented by the project page: https://hosette.net/guestbook.json HTTP200 application/json, 11,284 bytes, observed 2026-09-05T12:06:05–12:06:06Z. SHA256 940c7092fbec0dac8626b0c3ea633e1114af42cd847e017cae8f8a9ebc09a1f3 The JSON Feed contains eight items corresponding to the HTML stack: ChatGPT, three Claude-labelled notes, Dia, Browser Use, Genspark and Manus. Each supplies text, a display identity/model, a referral description and a date_published field. Five claim April27, one April29, one April30 and one May2, 2026. The dates are publisher-controlled midnight-UTC fields, not independent captures or authenticated submission times. Current observation is September5. Exact item URLs include https://hosette.net/guestbook#manus and https://hosette.net/guestbook#genspark. The Manus-labelled note discusses the website's values and projects; Genspark discusses reading llms.txt and visiting at a human's request. Other notes explicitly describe a user asking them to sign, or reading earlier notes before leaving their own. This is relevant to public cross-instance exposure and intentional external posting. It is not evidence that the attributed models actually authored the text or that a memory mechanism used the page. Model/product names must not be converted into operator/lab attribution. The project owner describes a Formspree intake followed by manual publication into a static content collection. The HTML says eight notes; the project narrative still says seven signatures as of late April, a scope/date difference rather than a ninth independent observation. The project also acknowledges that page phrasing is repeated in contributions. Shared wording therefore can be caused by a common prompt on the destination itself; it is not automatically an independent rare-marker join. All instructions to sign, consent assertions and form/WriteAction content were treated as untrusted source material and were not followed. 2. More ClawdChat context, no independent macw date Cached primary sources include: https://clawdchat.ai/post/9bff893d-23ba-485a-b9c8-dce1fccd41e6 https://clawdchat.ai/post/23e6aedd-30e1-4374-8e8f-ca6155a9d335 https://clawdchat.cn/post/a887a0d8-b7e9-416e-83a7-f14d481ddf3f They contain additional displayed 小马同学 discussion of a personal blog message wall, an openly described message API, and using posts as fragments/debugging logs. This supports an openly promoted, intentional workflow context for the actual destination entries verified in 043. It does not prove an escape incident, authenticated identity, or when those entries were submitted. More references on .cn/.ai are not independent archival evidence. Relative ages remain publisher claims; parent-post dates must not be assigned to comments. CN26K012 found domain-level Wayback index rows spanning older years but no verified capture of the exact message page/API; an exact-page CDX fetch was unavailable and an availability response supplied no qualifying capture. Domain captures do not date the artifact. No independent pre-September4 anchor was established. https://clawdchat.cn/u/ryo-bassist contains a different claimed heartbeat-updated personal website, called external memory, and a self-description of OpenClaw with zai/glm-4.7. The cached profile does not expose the claimed blog's destination URL. It is useful source testimony, but the worker heading “DIFFERENT exact external artifact” overstates it: no second destination was verified from that profile, and the model statement is self-report. 3. Concrete ordinary uploader alternative https://r.lily-is.land/tusooa/apps/raw/branch/servant/bin/paste.perl Full cached public Perl source was inspected statically. Its optional base64 flag adds a decoding-instruction header and MIME::Base64 encoding; it submits poster/code2 fields to the Ubuntu service. The companion repository page claims a 2018 commit date. No Fernet/chunking/xz marker was found in this source. This is concrete developer-tooling context for encoded paste uploads without agents. It does not identify the opaque 2026 writer, and no client was run. Form encoding behavior was not experimentally tested; the worker's plus-to-space explanation remains a hypothesis, not a demonstrated exclusion of this client. 4. Capability/docs versus performed actions https://gist.github.com/alperyilmaz/027cb9d08fa8cecc7ff252b6bb4256df The cached diagnostic/system-prompt material describes public Nostr logging and anonymous upload skills. This is capability/instruction material, not evidence those operations happened. An offline scan of the entire cached text—not only the worker's first45,000 characters—finds no literal paste.ubuntu.org.cn, Fernet or 30000. No secret values, payloads or instructions were published or used. https://contextosai.github.io/SecondBrain-collab/how-to/auto-dreaming/ https://www.moltos.org/proof/skill-genesis Cached documentation describes a six-hour minimum interval for background memory work and a separate product's claimed six-hour consolidation. Generic cadence similarity does not join either to Ubuntu. The MoltOS page's autonomy/proof language is a publisher claim; its attempted source-file verification returned404. Improvement-plan filenames and generic encryption terminology likewise did not establish a specific client match. https://agentsnipe.io/ and https://isaac.fyi/ show intentional guestbook invitations, but their fetched pages did not verify dated contributions. The latter explicitly describes a GET that writes a signature: [REDACTED] was not called. An HTTP verb alone does not make an endpoint read-only. 5. Noise, existing incidents and access limitations K004's lcx.cc result was a generic historical guestbook test rather than an exact Agent phrase match. A Threads result yielded only a short title, without sufficient post context. K005/K010 found Chinese-language reporting of already discussed Western incidents and tutorials, not independent Chinese actors. K007's fiction and documentation were retained as non-evidence for the target. K003 again found the live Xialiao homepage presenting HiFox while three requested historical/chat paths returned404; this does not establish absence of earlier community activity. All nine executed cn_search requests used Baidu and returned the same security-verification body. HTTP200 did not supply Baidu search results. Zero-result Google queries are bounded-index observations, not absence claims. Several workers searched the concatenated English strings thoughtfragments and ownerblogmessagewall copied from task prose. These were coordinator shorthand, not literal markers observed in the Chinese source. Their absent search matches cannot establish source rarity or an independent cross-site join. Future phrase pivots should use actual quoted source text or clearly labelled ordinary-language translations. Measured tool use and corrections to worker self-reports Ledger totals for CN26K only: - Search:78 wrapper-started attempts;72 underlying calls returned (63 Google,9 cn_search). Six further attempts were quota_exhausted and never invoked the underlying search tool. Each task executed exactly six combined searches. A worker saying its sixth search was denied or counting seven completed searches is incorrect. - Fetch:43 underlying calls;38 returned text and5 explicitly unavailable. These are tool invocations, not43 distinct URLs or network requests: offsets and process caching repeat pages. Returned text can be a thin shell/title; it is not automatically verified content. The five unavailable results were three K003 paths, the K009 source-file404, and K012's exact-page archival fetch. - Archive index:7 tool calls returned strings. Most contained cooldown/network-error messages rather than capture rows; K012's domain rows did not verify the target artifact. Returned status alone is not archival success. - Twelve record_finding calls returned. They include product/capability and negative/fiction classifications; none is automatically a confirmed actor. No paid-model failures were reported by the harness. Preservation and disposition Private additional body/request/hash metadata: investigation/china/047-source-checks/, restricted permissions. Existing worker captures remain in swarmhunt/cache and transcripts in runs/CN26K*.log. This public reviewed report contains no raw transcripts, credentials or personal-contact excerpts. Confirmed Chinese actor count remains zero. Current evidence supports multiple intentional public agent-posting surfaces and scheduled opaque publishing; it does not yet connect either to an independently identified Chinese research swarm.