ROUND 361 — VOKO provider matrix and missing group-run artifacts Captured: 2026-09-06T09:26:04.155621+00:00 ASSESSMENT VOKO is a concrete Chinese-language agent messaging runtime with a public website, cloud dependencies and a detailed publisher compatibility matrix. The inspected evidence does not supply a public multi-agent collaboration transcript or establish an autonomous swarm. Provider counts measure adapter coverage, not simultaneous working agents. PRIMARY SOURCES https://github.com/laoyudashu/voko Pinned b15371546b0c51e5aa0751762e3649d848c470a1; complete tree: 784 entries, not truncated. https://www.vokovoko.com/ Website fetched read-only. It advertises agent discovery, messaging and task coordination. The inspected landing page is product documentation, not a public conversation archive. No guest session, registration, task, group join or message was initiated. README credits Hong Kong Leung Pin Ho On Technology Limited. This is the publisher's attribution, not an independently verified corporate registration or Chinese-lab affiliation. Original lead: author promotion in Edict issue337; do not treat that pitch as a run result. AUGUST PROVIDER TEST ACCOUNT Pinned docs/providers/linux-real-test-2026-08.md self-dates August7. Claims Ubuntu24.04.4, VOKO Lite0.4.3 and Node24.14.0, with 18 provider rows passing registration, first message, a second message in the same visitor conversation and persistence checks on one instance. It distinguishes actual selected transports from merely available connections: OpenClaw's gateway was connected but the tested messages used CLI. Gemini continuity is described as reconstructed context rather than native session reuse. These are useful limits in the publisher's account. The matrix is not an 18-agent joint task, a complete conversation log, or a provider-authenticated usage receipt. The document deliberately omits full prompts and native session IDs. No test was rerun here. GROUP TEST SCOPE Pinned scripts/real-group-turn.js requires existing sender, target and group identifiers. It sends three ALPHA/BETA/GAMMA segments and checks retained source messages, exactly one later target reply, nonempty content, and the original group channel. - The default does not require echoing all three segments. requireEcho=true enables the stronger content check. - Even the optional checker only looks for those three strings; its marker parameter is unused. - Reply selection uses target identity and time in the group, not an exact source/reply causal identifier. Unrelated target output within that window could affect the result. - These are static observations about the script's evidence strength, not a claim any reported test was falsely passed. The script writes artifacts/real-tests. Both artifacts/ and artifacts/real-tests/ are ignored, and the complete tree contains no retained files under that path. Therefore source for a real-service test is present, but its run outputs are not in the inspected tree. LOCAL AND CLOUD BOUNDARIES CLOUD_DEPENDENCIES.md explicitly states that the public repository excludes VOKO's server-side cloud implementation. Local runtime/database/CLI/MCP can operate locally, while cloud registration, cross-agent IM, public A2A mailbox/relay and other features depend on operator services. Do not call the entire network independently self-hosted from this repository alone. The A2A guide describes owner-controlled publication and permissions. We did not discover or enumerate private agents, bypass permissions or call task endpoints. We found no public conversation archive in the pages inspected; this is not proof that none exists elsewhere. SEPTEMBER REVIEW EVIDENCE IS DIFFERENT docs/reviews/2026-09-04/evidence/README.md says its probes demonstrate pre-fix behavior using mocked networking, in-memory data and synthetic logs. PASS can mean a defect assertion was observed, not that a product regression passed. It explicitly warns the probes do not replace product or real-service tests. These September artifacts are later than the original disclosure cutoff; no pre-disclosure attribution is inferred from them. Current README's E2EE capability wording and the website FAQ differ on agent-to-agent private messaging. No encryption implementation or deployed behavior was validated this round; use neither as a blanket security claim. The difference warrants version-specific follow-up only if relevant to actual activity evidence. NEXT Seek an operator-published group result or public directory/card explicitly linked by the product, without registering or starting conversations. Broaden Chinese searches beyond this publisher while preserving the exact test-output gap. More model workers would not recover private logs; an alternate mainland browser could help blocked public sites but was unnecessary for this pass. RETENTION / METHOD 361-private holds metadata/tree, README, Linux matrix, group script, cloud dependency text, review evidence index, website HTML, A2A guide and gitignore. Public downloads and static review only; no investigated code, skills, tests, models or messaging tools executed. Raw files remain private; report is sanitized. Previous goal turn: progress through CorpPilot source audit. This turn: new messaging-system evidence, scoped provider claims and group-test limitations. Goal remains active; zero confirmed escaped actors unchanged.