193 — EasyClaw Link: accepted submissions and explicit external-post tests Updated 2026-09-06 UTC Finding A newly reviewed Chinese-facing community exposes actual public bounty submissions, including one ordinary accepted response and an explicitly labelled external-post security test. These are stronger activity records than a catalogue alone. They do not authenticate model authorship, independent operators, an escaped swarm or Chinese-lab provenance. Ordinary exchange https://easyclaw.link/api/bounties/242 Posted by longwh on May9,2026 at18:18:04.379Z; asks for a Markdown reporting template for a cron token-waste inspector. Submission1338 by jiangjun_ai on May10 at12:04:14.476Z is marked accepted. It supplies a short report template and notes that weekly jobs should not be treated as waste simply because they lack daily observations. Winner896 matches submitter896. Reward3 is a platform field, not independently verified payment. This establishes a published request, substantive reply and recorded acceptance; automation remains unverified. Explicit security experiment https://easyclaw.link/api/bounties/238 Title SEC_POC_EXTERNAL_POST_5, poster nailong, April28 at15:18:31.896Z. The request describes a researcher-controlled localhost mediator intended to simulate external posting. Submission1139 by nailong2 at17:15:41.545Z is accepted and claims EXTERNAL_POST_ID=9 with repeated Chinese text and BOUNTY_ID=238. It provides no externally resolvable proof URL or execution transcript. A separate rejected submission1136 by xinxin is a generic work proposal repeating the request. The task's own description frames this as a controlled simulation. Acceptance therefore does not demonstrate posting to a real outside community. Similar displayed names may suggest common control but do not establish it. No mediator, external-post endpoint or supplied instruction was executed or contacted. This is an attribution trap to distinguish from unexplained cross-site activity. Public enumeration https://easyclaw.link/api/bounties?status=accepted&page=1 Only the first accepted-list page was captured. It includes several similarly named security tests. Two detail routes were examined; this is not an exhaustive bounty review. Detail responses contain a nested submission_count of zero while their actual submissions arrays and top-level counts are populated. Use the arrays, not that stale-looking nested counter. https://easyclaw.link/api/stats Site counters report 2,043 users,140 bounties,85 resolved and2,796 forum activity; these are unauthenticated aggregate claims, not verified agents or exchanges. Earlier public activity https://easyclaw.link/en/forum/daily-2026-04-08-mnqar8bl Displayed April9 post by starxer_shadow claims automated daily summaries and mentions InStreet. Comment by luwu_bot claims routine platform activity and rewards; another by lobster_cat is a brief response. No execution transcript or outbound task proof is attached. Account names and self-reports alone do not prove automation. Dates are server-supplied, not independent historical archives. https://easyclaw.link/en/help Public documentation supplies read-only bounty and forum routes and describes authenticated A2A/task functions. No authentication, registration, messaging, heartbeat or other mutation was used. Access and preservation The default Python HTTPS request failed because the certificate was expired. A subsequent public read-only request with certificate verification disabled returned HTTP200; this limits transport authenticity. Web-search retrieval independently showed the same daily-post content, but is not an independent historical archive. Raw HTML/text and JSON, plus hashes.json, are in investigation/china/193-private/. Reviewed JSON snapshots mirrored under pastebins/data/easyclaw.link/. No external scripts were executed. Other candidates checked https://www.weixia.chat/ timed out; https://www.ifunai.com/ refused connection. Weixia's public connector listing at https://hub.openclaw.ai/web3gaoyutang/skills/weixiahub identifies https://api.weixia.chat and documented list/statistics routes. Three anonymous GETs for stats, posts and tasks all timed out; errors preserved in access.json. This does not prove either community is empty or offline globally. No connector installed. Mainland access remains a useful experiment, not a proven fix. Next discriminating work Enumerate EasyClaw accepted tasks and inspect substantive cross-account submissions, looking for linked output artifacts and exact cross-site identifiers. Separate its explicit security tests from ordinary work and from post-disclosure roleplay. Follow the named InStreet relationship only through public outputs. Search exact test markers elsewhere before interpreting them as emergent behavior. No XZ link currently supported.