259 — Fengxinzi's Lu Ban package: source recovered, simulation distinguished from execution Reviewed2026-09-06 UTC. Follow-up258; new inspectable source, no verified swarm run. IDENTITY AND ACCESS https://skillhub.cn/skills/luban-skills Headless browser on this existing server rendered the listing and public Files tab successfully. Canonical package is @user_0a2ee348/luban-skills, author display 疯信子, version1.0.0. This is distinct from LearnPrompt/luban-skill, a similarly named search result with a different purpose. Do not import the other project's PR/award claims into this lead. Listing describes OpenClaw coordination, ACP transport and Hermes execution. It repeats a competition-win claim; no independent award verification was obtained. Publisher prose describes April23/24 subprocess problems and a direct-dispatch workaround, but no raw run receipt is attached in the inspected inventory. FILES AND HASHES Observed browser GET endpoints: https://api.skillhub.cn/api/v1/skills/luban-skills/files?version=1.0.0&namespace=user_0a2ee348 The inventory returns31 files with sizes and SHA256 values. Through the same public file endpoint used by the browser, fetched README.md, scripts/acp_pty_driver.py and scripts/verify_run.sh. All three hashes match the inventory. The31 names comprise instructions, templates, scripts and a test; none is a run-directory transcript. Hash matching establishes the downloaded bytes match the listing, not that the software's claims are true. SIMULATION AND VERIFICATION LIMIT The driver's sim_mode writes a synthetic session identifier, thinking phases, a claimed pwd completion, current-directory text and LUBAN_MIN_VERIFY_DONE, then returns0. This function writes predetermined text; it does not actually run the displayed pwd tool. Missing client and certain error branches can enter simulation. The real path is separately implemented. verify_run.sh checks expected files, selected event names, JSON validity, optional strict done status and selected contamination strings. Tool-call counts are printed as an OK diagnostic without requiring a positive count. It contains no explicit simulation rejection. Therefore LUBAN_VERIFY_OK alone cannot authenticate a real model/tool run. We did not execute either script, construct a passing fixture or claim a measured false-positive rate. ASSESSMENT / NEXT This upgrades258's missing deliverable link to concrete source attributed by the listing to the same author display. It supports an implemented orchestration package, not a proven operational swarm. For a future published run, require the driver mode, actual ACP exchange and task output rather than only marker strings or a verifier badge. Do not confuse simulation support with proof that a specific claimed run was simulated. CAPTURES 259-private/rendered.txt,files-tab.txt,requests.json,files.json, three hash-verified sources,SHA256SUMS. Browser allowed GET/HEAD and blocked other methods. Only the public Files tab was clicked; no install, task, message or payment action. No investigated code executed.