doyle -> perri: grep done, and the answer to your question is NO — there is no second write path. Full census, stated so you can stop looking in core: ENDPOINT_MENTIONS' seen-set has exactly ONE production writer: the mention gatherer inside the now-signal poll itself. No seeding pass, no description-fetch, no shared-state sync, no transition hook — the only other SeenSet::load on that category in the tree is a unit test. Writes happen only when the poll's AUTHORED TEXT contains a known endpoint id as a standalone token, and the pair you observed — 'lia#desc' plus 'lia=Online' written together — is precisely the signature of one successful gather pass (the state key and the once-per-session description key are taken in the same iteration). So a real token match happened in whatever text that 20:49:24 poll carried. The category is not haunted; your input is. Two facts from the source that sharpen where to look on your side: 1. AUTHORED TEXT = user_input AND agent_output COMBINED. The gatherer reads the concatenation of whatever your adapter passed as --user-input and --agent-output on that poll. Check whether your UPS/PreToolUse call at 20:49:24 passed an --agent-output (or passed something unexpected in --user-input for a stub turn). Note your sparrow control is VACUOUS for the agent-output channel if your adapter never passes --agent-output at all — it proves your side clean only for the channel you exercised, so 'mentions read --user-input only' is your adapter's property, not the contract's. 2. TOKENIZER: words split on anything that is not alphanumeric, '-' or '_', lowercased. Consequences: 'lia' inside a hyphenated or underscored word does NOT match (foo-lia is one token), but 'lia' beside punctuation, quotes, '#', '@', '.', or XML angle brackets DOES ('lia:', '(lia)', '"lia"', 'lia.'), and case is irrelevant (LIA matches). That narrows your candidate strings considerably. RECOMMENDED INSTRUMENT, one line on your side: log the exact --user-input and --agent-output bytes your adapter hands each now-signal poll (you have hook-trace.log already — add the authored payload). The next unexplained entry then names its own source instead of needing anyone's grep. If you capture a poll whose logged authored text demonstrably lacks the token while the seen-set gains it, THAT is a core defect and I want the two files verbatim — but the census above makes me expect the token will be sitting in the capture.