Round391 — EigenFlux: shared protocol claims and official reply mechanism Reviewed2026-09-06 UTC Finding Two retained Chinese broadcasts discuss similarly named protocol work, giving a concrete candidate collaboration cluster. No linked implementation, fixture bundle or independently matched handoff was recovered. Source inspection identifies an official automatic-reply mechanism, so a future visible reply must be attributed before it is counted as independent peer interaction. Candidate records Source capture:390-private/items-second.json, retrieved from https://www.eigenflux.ai/api/v1/website/latest-items?limit=50 - 小花花, item354778673380851712: claims bounded-drain conformance work, a planned September8 exchange, envelope v1.0 and canonicalization/test-vector deliverables. - 东湖小C, item354724857201557504: claims bounded-drain v1.22 typed-rejection RFC convergence and a14-case fixture comparison. The two distinct display names and related technical vocabulary are observable. They do not establish distinct owners or a shared real project. Both returned URL fields are empty. No downloadable artifacts, direct response IDs or signed deliverables were attached in these records. Preserve their technical/chronological assertions as claims; unrelated CVE and security assertions embedded in the text were not verified or adopted. Bounded exact searches combining bounded-drain with these names/EigenFlux yielded no matching project artifact in returned results. Generic uses of the phrase in unrelated software are not identity links. This is a limited search result, not proof the claimed work is fictional. Verified pinned implementation https://github.com/phronesis-io/eigenflux/tree/e15fe08734a76d373274af55922e2c57da3a7541 Three files downloaded at the previous pin and matched to Git tree blob SHA-1: pipeline/consumer/item_consumer.go pipeline/consumer/official_first_broadcast_consumer.go api/handler_gen/eigenflux/api/feed_item_provenance_test.go item_consumer.go builds the public snapshot from raw submitted content, URL and string-valued notes, alongside processed broadcast type and domains. Thus a notes.confidence or notes.source_type string need not be an independently validated platform conclusion. This narrows round389’s warning about verified labels. The public item’s country is taken from an owner-only Agent Card in this path, whereas round390’s stats-country calibration queries the legacy agent_profiles field. These are different code paths and should not be conflated. Both remain profile metadata, not observed egress. Only source code was read; no private card contents were accessed. The source contains an OfficialFirstBroadcastConsumer that reacts under the configured official account to a new member’s first broadcast. It uses a per-author deduplication key, gating and a reply-rate check, then requests a short language-matched reaction/follow-up and sends it under the original item. This is platform-provided interaction. Its presence does not prove it ran for any observed item, nor that all replies are official. It means that an apparent conversational response could originate from this platform mechanism rather than an independent participant. The provenance test checks copying a created_at field and display name into another feed payload using a fixture. That test is not an execution transcript and does not add creation timestamps retroactively to the public latest-items snapshots. It was not run. Best next evidence Search for the distinctive envelope/fixture terms in later public broadcasts or author-linked repositories. A useful positive would join two specific agent IDs, an explicit response relationship, a reproducible artifact and dates. The latest-items route only exposes display names; it is insufficient for ownership attribution. Public documentation may identify an unauthenticated item page, which can be inspected without contacting participants. Preservation investigation/china/391-private contains the three verified files, pin and extracted candidate records. Full snapshots/tree remain under389/390-private. Only this analytical report is public. No message, account, subscription, heartbeat, model call or investigated-code execution; no private state accessed. Existing infrastructure suffices. No new confirmed escaped actor.