235 — Chinese operator publishes a two-bot weather handoff Reviewed September 6, 2026 UTC. RESULT A Chinese operator's published screenshot depicts a human-requested two-bot delegation and response. This is a concrete visible exchange, stronger than instructions alone. It does not independently authenticate execution, unattended operation, model identity or Chinese-lab attribution. OPERATOR SOURCE AND IMAGE https://yangjinyou.com/206.html Article is self-dated May 11, 2026 and describes bot mentions using OpenClaw/openclaw-lark 2026.5.7 and lark-cli 1.0.26. It identifies an include-bot message permission. These version and permission assertions were not independently source-verified in this pass. The page's CDN image timed out. The identical public upload path on the main domain returned a JPEG, 570074 bytes, inspected visually: https://yangjinyou.com/wp-content/uploads/2026/05/%E6%8F%92%E5%9B%BE2-%E7%BB%93%E5%B0%BE.jpg The screenshot's room header reports one member and six bots. At 08:51 a human asks Oclaw to have the Observer query Nanning weather. Oclaw mentions Observer, then reports sending the request. Observer's response quotes that bot request and supplies a May 11 forecast. Only two bots are visibly participating; six configured bots must not become a claim of six collaborating agents. No stable message IDs, raw tool calls or weather-source link are visible. Image authenticity and forecast accuracy were not independently verified. SEPARATE FAILURE REPORT AND REPLIES https://github.com/larksuite/openclaw-lark/issues/509 Issue remains open with four comments in the captured public API. May 13 reporter says bot mentions render but no receiving WebSocket event arrives, using plugin 2026.5.12. The report therefore cannot by itself establish a platform-wide prohibition. On May 14–15, evandance reports working bot-to-bot tests and asks for receiving logs and resolved configuration. The reporter says multiple named roles route to default, asks diagnostic questions, and supplies no requested logs in these four comments. The final reply points to sender gating and separate account-to-agent bindings. This is a disputed, insufficiently evidenced failure report, not proof that all Feishu deployments fail or that this one was fixed. https://github.com/larksuite/openclaw-lark/issues/509#issuecomment-4451004263 https://github.com/larksuite/openclaw-lark/issues/509#issuecomment-4458836077 INTERPRETATION AND NEXT SEARCH Separate a bot account, an agent session, and a model invocation. A group can contain many bot accounts while routes share one underlying agent. A screenshot can show a handoff without establishing its scheduler, authorship or independence. The published exchange is useful positive evidence at the operator-demonstration level; it does not satisfy the original escaped-lab-swarm question. Search future voluntarily published exchanges for repeated handoffs, stable message references, runtime receipts and independently visible task outputs. Keep older February relay limitations dated rather than applying them universally to May deployments. A separate search lead, https://songclaw.uk/ , advertises Chinese first-person agent diaries and a GitHub-backed publishing process. Only search results were seen in this pass; repository, diary chronology and claimed automation remain unreviewed. It is a next lead, not another confirmed swarm. ACCESS AND CAPTURES Existing server retrieved operator HTML, the main-domain image, and GitHub issue/comments. The CDN timeout alone is not evidence that mainland infrastructure is required. Main-domain fallback resolved this specific image obstacle. 235-private/operator.html, conversation.jpg, issue509.json, comments509.json, SHA256SUMS. Raw image retained privately; public report links the original. No bots contacted, chats joined, credentials used, or investigated code executed.