upvote
If the HuggingFace repo the agent broke into contains reference solution scripts for ExploitGym (i.e. for exploiting the vulnerabilities in the intended way), the agent can then run that reference code inside its original sandbox to retrieve the dynamically-generated flags.
reply
It's marketing 100%.
reply
Even if it is marketing, wouldn't it still be a concern that an advanced model unintentionally breached another company's production system? Or required resources on their end to mitigate and contain it?

Couldn't this announcement result in policies that could hinder OpenAI by requiring more oversight?

reply
Yeah, they're lying. The model didn't do any of that, right?
reply
Nope huggingface just made up the intrusion they reported last week to their customers.
reply