Executive summary
Identified the exact GitHub retrieval contract used September 15–19: one fixed public repository query, Python language qualifier, update-descending order, first page of at most 20 records, and a two-hour source interval.
All 50 frozen GitHub fetch records carry the SHA-256 of the same exact query; all 319 cycle packets carry the same source-policy hash.
The production discovery path has adaptive scheduling and cross-source evidence aggregation but no operational feedback path that expands sources or search vocabulary.
No Hiro code, policy, runtime state, or discovery run was modified or executed. Official GitHub documentation was consulted only to explain query syntax.