There's a few issues here.
First - you probably shouldn't use data filelist; set filelist; if you're doing something like this. Make a new dataset.
Second - filename is not executable. It is declarative. You can place it inside the data step, but you shouldn't, and for precisely this reason: it makes you think it's doing something inside the data step. It's not. It's doing something, period, and then the data step happens, later (even when placed here).
Third - you aren't using infile properly, but that's really a consequence of Second. You need the filevar option on infile to allow it to do something different here.
Fourth - you probably don't really want to just read arbitrarily from the project.xml. Really this whole thing is probably not what you want to do... I've done what you're doing, and it's doable, but not this way. But that's probably a bigger question.
If this were to work, what you'd do is this:
filename a zip "c:\doesntmatter.egp" member="project.xml";
data files;
length fname $255;
infile datalines truncover;
input @1 fname $255.;
datalines;
c:\myfile.egp
c:\myfile2.egp
c:\myfile3.egp
;;;;
run;
data egp;
set files;
infile a filevar=fname pad truncover;
input @1 first_line $512. @;
put first_line;
run;
The filename statement doesn't really do anything, but I show you where it would go. You see the filevar on the infile statement - that points to the fname variable on files. Then it reads in from there.
My general suggestion is that you should probably use the xml libname engine here; figure out what you want to do on a per-xml basis, write that out as a macro, then call the macro for each line in the file name dataset (using call execute probably, or if you must, dosubl). You don't have to use the xml libname engine, but it'll simplify things most likely.
If you're only using one file, then you can specify it directly in the filename statement I showed above, and just use infile with that filename (infile a; here, but please call it something more sensible than a). But again, it's silly to read it in this way - use the libname engine, as it'll parse out the xml for you.
Edits, to remove incorrect information confirmed by Tom's answer. Even though it does work, I don't recommend using infile here - read it with the libname engine, it'll save you loads of time.