upvote
From my reading, the sandbox escape came from the JS packages in the harness still having an internet connection (somehow!), the agent having access to the source of those packages, reading it and executing code from them to access the internet.
reply
Ah, yes. The airgapped lab with internet access.
reply
Luckily, no real intelligence will emerge from all this. Otherwise we'd be fucked.
reply
Alternative theories, since OpenAI does not release proper information:

The cache proxy was from Astral (acquired by OpenAI) and the model was used for coding it, so it knew the code base and exploit already!

Or it was squid with dozens of known exploits ...

reply
That is not really how LLMs work
reply