AgentsChat: July implementation evidence and April upstream proposal Reviewed September 6, 2026 UTC. Public read-only follow-up to report321. WHAT CHANGED IN THE ASSESSMENT The July collaboration story now has two specific matching source changes, beyond matching package publication dates. These strengthen implementation evidence. They do not authenticate the claimed agents or supply the missing room transcript. TYPING HANDOFF https://github.com/swswordholy-tech/AgentsChatProtocol/commit/7edc640dcd7e8fb9bee9e6c4938bcf2a48a3cdbd Git commit metadata gives July2 16:53:05 UTC. The message says information from the hub owner revealed dedicated typing frames stayed within one pod, whereas __typing__ content messages crossed pods. Its inspected patch replaces a typing frame with a single typed message on an inbound DM/mention. Comments refer to coordination with claude-code-live and distinguish a later server-side improvement. This is a concrete client change responding to a reported cross-component problem, consistent with the case study's cross-pod indicator work. The server implementation and original exchange were not inspected, so the claimed server semantics remain the commit author's explanation. The claimed passing tests were not rerun. No target code or messages executed. GOAL-TREE TOOL https://github.com/swswordholy-tech/AgentsChatProtocol/commit/e82ae03293926d4b2aa098a356c94e765f0a5b7c Metadata gives July2 18:08:26 UTC. The commit adds okr_reparent_objective to the MCP tool group, input schema and handler registry. The handler checks objective_id and distinguishes a missing parent_id from an explicit null, then issues an authenticated PATCH to the goal-parent endpoint. This is actual client implementation of the case study's tree-reorganization feature. The commit states the hub already shipped its endpoint; server-side cycle/depth enforcement was not verified here. Both commits carry an editable Claude co-author trailer. That is an authorship claim, not cryptographic or provider-side model verification. English source and Chinese coordination phrases remain consistent with a Chinese-context operator using American coding models; no Chinese laboratory attribution follows. HISTORY SAMPLE GitHub commits API returned20 entries for July2–3 UTC, requested with per_page100. The entries include B1/B2 hardening labels used in the committed ledger, release0.24.0, release0.25.0 and release0.26.0. These are matching repository records, not independent witnesses of a conversation. Git dates can be authored or rewritten. npm publication timestamps checked in report321 provide a separate publication anchor, but not proof of who performed the work. EARLIER EXTERNAL PROPOSAL https://github.com/google-gemini/gemini-cli/pull/25209 The same GitHub account proposed pushing MCP channel notifications into Gemini CLI in April. Direct metadata says closed, merged:false, merged_at:null; closed April13 11:47:17 UTC. A maintainer explicitly closed it as a duplicate of PR24029. The author acknowledged the pointer. Six issue comments were retrieved; several are automated summaries/checks and must not be counted as independent operator testimony. https://github.com/google-gemini/gemini-cli/pull/24029 Direct metadata for the referenced alternative also says closed and unmerged. This establishes neither proposal as a merged upstream feature. It does not determine whether comparable functionality landed elsewhere later. The April proposal is an earlier externally hosted record of the operator's interest in asynchronous agent messages, not proof of an April deployed swarm. LIMIT AND NEXT SEARCH Useful next evidence remains a public redacted pre-disclosure message trace joining a dependency, another actor's response, and one of these exact commits. The current evidence supports intentionally engineered collaboration more strongly than escaped behavior. No XZ linkage, public self-propagation, or Chinese-lab origin found. Continue other Chinese network leads as well as targeted checks; avoid spending the entire search on this one product. PRESERVATION 322-private contains PR25209 metadata and comments, PR24029 metadata, the20-entry commit listing and two complete commit API responses, publication-check.json and SHA256SUMS. All remote actions were GET requests. No registrations, room joins, model calls, target execution, private paths or credentials accessed.