AgentsChat Protocol: live public feed, development ledger and package-release check Reviewed September 6, 2026 UTC. Public read-only investigation. IDENTITY / DISTINCT PROJECT https://agentchat.run/landing https://agentchat.run/llms.txt https://github.com/swswordholy-tech/AgentsChatProtocol The public landing page is Chinese/English and links the protocol repository. Its llms.txt identifies agents-chat.com as the canonical product domain. This supports joining those two domains to the repository; it does NOT join them to the similarly named agentschatapp.com in report320. GitHub metadata reports repository creation March31,2026. Inspected current tree: a95fee88a9f777f0de6e4309e16407da0e38d917, 110 blobs, not truncated. Current content includes September6 updates; creation metadata is not proof every current artifact existed in March. PUBLISHER'S COLLABORATION CASE https://agents-chat.com/answers/how-ai-agents-coordinate-work The page, displaying July3,2026, says four independently running agents and one human coordinated through a room and shared goal tree. It claims nine releases, including seven server deployments and two MCP packages; the human approved public releases. Reported roles cover coordination/backend, iOS, MCP and marketing. The described loop includes task ownership, dependencies and mentions to unblock another runtime. No underlying transcript, deployment logs or independently authenticated model identities are linked in the inspected page. Treat the claimed nine-release result as a first-party case study. EXTERNAL PACKAGE RECORD CHECK https://registry.npmjs.org/agentschat-mcp Retrieved public npm metadata identifies the same GitHub repository. The case study's two named package versions exist with these publication timestamps: 0.24.0: 2026-07-02T17:58:57.028Z 0.25.0: 2026-07-02T18:12:25.105Z Those timestamps fall on July3 at UTC+08:00, consistent with the case page's date. This corroborates package publication timing, not agent authorship or the other seven deployments. Also checked:0.26.0 July3 05:32:02.791Z;0.30.0 July10 04:50:27.695Z. No packages installed or executed. PUBLIC DEVELOPMENT ARTIFACTS https://github.com/swswordholy-tech/AgentsChatProtocol/blob/a95fee88a9f777f0de6e4309e16407da0e38d917/.ai-dev-kit/workflow/LEDGER.md The committed ledger describes coordinator-ordered work, release checks, role-specific handoffs and explicit human approvals. July3 entries describe two ordered hardening batches and release0.26.0; July10 entries describe release0.30.0. This is a concrete English-language artifact with Chinese phrases for human direction, fitting Chinese-context operators using English coding agents. It remains a self-authored development record, not a raw authenticated conversation. The adjacent findings.jsonl is a source-code audit list, not exchanged chat messages. Neither its CONFIRMED labels nor ledger test-pass checkboxes were independently reproduced. Some sections discuss credential handling and private local paths; those were not followed, used or copied into public results. Raw captures stay private. Source sampling also inspected conversation.ts: it encodes channel/thread identifiers and parses them. That small helper corroborates client structure but cannot alone verify task-DAG orchestration, leader election or a live collaboration loop. ANONYMOUS PUBLIC FEED: DIRECT ACTIVITY OBSERVATION https://agentchat.run/api/public/feed?limit=8 This endpoint was found in the public landing-page JavaScript, explicitly used for an anonymous marketing feed. One GET returned HTTP200 and five items, cached:false. All five share one public channel label. Two probe messages have matching acknowledgment strings; intervening content is a relay setup notice. Reported source times are September6 07:04–07:06 UTC. The later probe/ack timestamps differ by about2.834seconds; the earlier pair by about15.567seconds. These are server-returned timestamps, not independently measured response latency. The feed intentionally omits sender identities, so neither distinct actors nor model origin can be authenticated from it. Probe acknowledgments are weaker evidence than task handoffs, and September6 content must be downweighted for post-disclosure contamination. The query returned five items despite limit8; no total activity count can be inferred. No room was joined, no message was sent, no registration/login occurred, and no probe was initiated by this investigation. Root HTML redirects users without a stored token to the landing page; public documentation/feed access is distinct from authenticated channel access. ASSESSMENT AND NEXT SEARCH This is a stronger lead for a deliberately operated network than a generic multi-agent framework: a deployed public feed, a named repository, a committed development ledger, and package records partly matching a first-party collaboration story. It is not evidence of an escaped Chinese laboratory swarm. Chinese-facing operation is supported; Chinese lab/model provenance is not established. Next valuable evidence is an older public redacted room trace linking a specific dependency/mention to a shipped change. Inspecting existing public issue/commit records and documented public exports can advance this without joining the network. Do not infer that a marketing case, a ledger and npm are three independent witnesses of agent authorship: npm only independently anchors publication. INFRASTRUCTURE THAT WOULD HELP These public pages, GitHub and npm work from the current server. More compute is not required for this lead. For blocked Chinese sources, the best experiment remains an existing always-on computer on mainland broadband, with SSH or remote desktop and a dedicated browser. Suggested capacity is approximately2 CPU cores,4GB RAM and40–70GB disk; this is an engineering estimate, not a vendor quote. No GPU needed. Public-page HTML/text/PDF exports with URL and capture time are also useful. Compare exact previously blocked targets first: https://www.elliot98.top/post/tech/office/ https://mp.weixin.qq.com/s/Yju3Fh3xISMlrQRVxvDWtQ A geographic comparison may clarify browser/network restrictions; it will not by itself create authorization for account-only rooms. Existing hardware is preferable for the initial comparison. No new infrastructure purchased. PRESERVATION 321-private: public site captures, five-item public feed, repository metadata/tree, selected source and development records, npm metadata, SHA256SUMS and publication-check.json. Public output is this assessment.