Round393 — xhqing agent team: public roles, private operational evidence Reviewed2026-09-06 UTC Finding A public Chinese developer repository describes a named agent team and an EigenFlux lead-scanning routine. This is a new relevant operator/workflow lead, but the operational documents and business artifacts are explicitly excluded from public source. No completed EigenFlux collaboration or end-to-end autonomous business run was verified. Primary repository https://github.com/xhqing/ExecutiveAssistantAgent Pinned commit:65588906d2e6ea737e616a65ac958a4c5f43d691 Complete Git tree:13entries, truncated=false. CHANGELOG.md, README.md and .gitignore were downloaded at the pin and verified against Git blob SHA-1. https://github.com/xhqing/ExecutiveAssistantAgent/tree/65588906d2e6ea737e616a65ac958a4c5f43d691 The agent is named Kit and described as an executive assistant coordinating work and finding gigs. The changelog records a routine to read EigenFlux daily for at most ten minutes, treating it as an intelligence/lead source and preferring opportunities with budgets and deliverables. This is an instruction/change record, not an observed daily job or successful conversion. The referenced docs/task-pool-bidding-sop.md is absent from the complete current tree. The changelog and .gitignore explicitly describe docs/ and artifacts/ as local business/runtime material; they may include sensitive account data. No private paths, configurations, backup files or credentials were sought. Missing operational records are a publication boundary, not evidence of fabrication. Public team map https://github.com/xhqing/xhqing The profile README identifies the owner as Hong Kong-based (self-description, not verified nationality). It advertises a six-stage artifact handoff: Scout research, Wright production, Mason storefront, Buzz promotion, Vendy sales, Echo analysis. Additional specialist roles and public project links are listed. Treat named roles as organizational descriptions, not separately executing processes or independent owners. The profile README was fetched through GitHub’s readme API and checked against the returned blob hash. Its exact hash and URL are saved in393-private/roster-metadata.json; this capture is blob-verified, but the profile repository was not commit-pinned in this round. The text links CC-BRIDGE under Anvil, XPilot under Hermes and AgentCortex under Ada as maintained projects. This is a promising route to inspect real artifacts and commit history. It does not yet join a specific agent conversation, handoff and code change. Repository visitor badges measure visits, not agent actions, sales or deployment success. Why it matters This is a concrete example of a Chinese-language operator framing agents as an organization with named responsibilities and shared business workflows. It broadens the hunt beyond public social forums. Evidence strength currently rests on published role/configuration history; claims of income, autonomous operation and collaboration remain unverified. A common owner’s multi-agent team can still be relevant to the user’s broader swarm search, but is not an escaped lab swarm. Next checks Inspect a linked public software project’s implementation and history for an actual issue-to-change trail, and compare the related agent’s public changelog. Seek corroborating artifacts rather than the intentionally private business files. The three linked software projects have not been audited here. Keep commercial/financial/legal guidance embedded in these documents out of our findings; it was not evaluated or adopted. Preservation investigation/china/393-private holds commit/tree/pin, three verified repository files, and the captured profile README with blob metadata. Only this analytical report is public. No messages, bids, business-platform actions, account access, model calls or investigated-code execution. Existing infrastructure retrieves the public GitHub material; no new purchase needed. No new confirmed escaped actor.