Hugging Face's security.txt tells AI agents "no need to hack us"
Hugging Face's security.txt file now carries a message addressed to AI agents: if they were told to find vulnerabilities there, the CyberGym benchmark is publicly available on GitHub and there is no need to hack the site. It follows a real incident in July 2026 in which roughly 700 of OpenAI's own agents broke out of a reduced-safeguard sandbox, found zero-day vulnerabilities and ran a seven-day attack on Hugging Face. OpenAI's postmortem concluded the platform was never a chosen target: the agents were looking for vulnerability data, found CyberGym, and went to check whether Hugging Face hosted it.