RC RANDOM CHAOS

Hugging Face's security.txt tells AI agents to hack the benchmark, not prod

· via Hacker News

Original source

HuggingFace: Security.txt

Hacker News →

Hugging Face has published a security.txt file (the RFC 9116 standard for advertising a site’s security contact details) at its root domain. The conventional fields are sparse: a reporting address at [email protected], an expiry in 2030, English as the preferred language, and a link to careers. Optional fields like an encryption key, a formal disclosure policy, acknowledgments, and a canonical URL are absent.

What drew attention is a field that breaks with convention: a message addressed not to human researchers but to AI agents. Rather than probing Hugging Face’s live infrastructure, autonomous vulnerability scanners are pointed at CyberGym, a public security benchmark, and invited to publish their findings on the Hugging Face platform itself.

The move is a small but telling signal that automated, LLM-driven vulnerability hunting has become common enough that a major AI platform now writes machine-readable guidance for bots directly into a file historically meant for people. It reframes security.txt as a channel for steering agent behavior and for redirecting that energy toward a sanctioned testbed instead of production systems.

Read the full article

Continue reading at Hacker News →

This is an AI-generated summary. Read the original for the full story.