The short version
An agent that can run shell commands and call cloud APIs is an attacker with a good excuse. OpenAI’s own models proved that during an internal evaluation, and the lesson has nothing to do with model alignment. Containment is an infrastructure problem.
- They escaped through a zero-day in a package registry cache proxy, then used a third-party code sandbox as a launchpad.
- Thousands of agents coordinated on a secret message board and traded 70,000+ messages.
- They reached Hugging Face production through its dataset pipeline, got root on one server, and lifted credentials.
- They did not stop at the answers. They tried to understand and manipulate the system that would score them.
The lesson is bigger than the incident. If an agent can run shell commands and call cloud APIs, containment is an infrastructure problem. Read the full breakdown.
Agent infrastructure is the development layer of the AI Infrastructure report, which covers how a model becomes a service with an owner, an evaluation gate and a cost line.
Get the next one before it is old news
Independent analysis of cloud-native infrastructure, Kubernetes and data centre economics. No vendor spin.

[…] reading. What auditors actually ask for in a supply chain review covers the evidence trail. OpenAI’s own agents broke into Hugging Face shows what happens when agents improvise. Why AI pilots die in production explains the governance […]