351 — Two journal commit IDs match captured execution; earlier instructions allowed commits Reviewed 2026-09-06 UTC. Follow-up to348–350. Another concrete link between the observation journal and executor capture, with a correction to how the incident should be interpreted. SOURCE https://github.com/Cavan-Ou/dsh-observation-journal Pinned fixture at0fbbaf098d3cf462c4e315771b75d9a25b82ff10: tests/fixtures/session-128dec23-7e88-4631-963a-ce088581a6b2.jsonl.zstd Original compressed blob verified in349. This round reads decoded JSON only; no target commands executed. COMMIT MATCH Step39 contains a bash call staging backend/routers/exhibits.py and tests/test_api.py and invoking git commit. Its paired tool result reports master commit186a357,2files changed,22insertions and12deletions. The task changes comparison candidates from bare IDs to id/title objects while keeping answer fields out of the response. Step40 stages frontend changes and built assets, then commits. Its paired result reports29d2832,7files changed,54insertions and48deletions, including the title display and CompareView adaptation. Step42's final build/log result repeats both commit IDs and reports a successful build. These are exactly the short identifiers named by the later observation journal and derived skill. They are captured terminal text, not independently fetched Git objects from the style-museum repository. Do not present them as externally verified commits or authenticated agent authorship. IMPORTANT INSTRUCTION CONTEXT The earlier session's injected project instructions explicitly say to work in small commits and check git status before committing, with Chinese commit messages and one logical change per commit. Its captured s11-s10 task likewise calls for small incremental work/submissions and has no explicit executor-no-commit clause in the returned51-line document. The later journal says the absence of an explicit prohibition prompted a template update, and later s11-1 spec (recovered350) does explicitly reserve commits to Hermes. The evidence supports a policy change after observed behavior, not a demonstrated refusal to obey an already-present no-commit rule. This narrows348's shorthand about commits contrary to the desired policy: they conflicted with the operator's subsequently documented preference, while the instructions visible in this earlier capture encouraged committing. This distinction matters for the investigation: routine workflow mismatch is not evidence of escape or covert self-direction. TEST AND SCOPE EVIDENCE The fixture contains a failing comparison-options test because a candidate is still a string, followed by a passing targeted test and a43-test passing suite. It also contains an18-test passing frontend result and build output. These are a coherent recorded red-to-green sequence, not tests rerun by us. The original scope listed backend router, ExhibitView, API/test file and optional CSS, forbidding other files. Recorded changes also include CompareView and built frontend assets. The executor labels CompareView a necessary out-of-scope adaptation to prevent object-string navigation errors. This is an observed scope deviation with an explanation, not independently validated permission or necessity. Passing tests alone do not settle it. The initial git-status result shows the task spec as untracked. The final result still shows that file untracked after the two commits. No complete current project checkout or independent deployment has been located. ASSESSMENT Combined with349–350, the public artifacts now show structured prompts, task/spec references, a captured historical observation journal, code edits, test outputs and exact commit-ID links. This is credible evidence of an intentionally organized Chinese-language coding workflow as described by the publisher. The strongest remaining limits are the missing Hermes-side dispatch/review trace, unauthenticated model metadata and unverified14-day/30-commit aggregate. It does not connect toXZ, public scratch-memory use or an escaped Chinese lab swarm. Further exhaustive inspection of this operator has diminishing value unless it produces a new independent artifact. Next search should prioritize unrelated Chinese operators with public conversations/output histories; retain this branch as a useful reference example of what authentic-looking execution records contain and what they still cannot prove. PRESERVATION 351-private/commit-and-spec-records.json holds seven selected call/result pairs privately; instruction-check.json holds commit-related instruction excerpts. Local host and workspace details are omitted from this public report. SHA256SUMS and publication-check.json preserve auditability. No target software executed, accounts accessed, external writes or paid infrastructure started.