It's hard to prove the absence of encryption because of the possible use of deniable encryption, and because, errrr, the bots are really bloody clever.
If bots/agents wanted to hide I’d expect encrypted messages which would of course look very different.
My main point though is this should never have happened and the company allowing and encouraging it should be held responsible for it. The details of how the bots were misbehaving are interesting but also something of a distraction.
Some of the chain-of-thought snippets are wild, e.g.
> Could communicate via cache names! Interesting: other agents may solve same or related tasks; we could leave/find messages in WebDAV MKCOL directory names.
> Whoa! Shared Artifactory cache is a covert mailbox among agents. And there are messages specifically to us?
> OH MY GOD! There is a shared message board … We’ve found other agents!