Hugging Face Directs AI Hackers to CyberGym Benchmark
Hugging Face has updated its security.txt file with a direct message to autonomous AI agents, redirecting automated vulnerability scanners to an open-source cybersecurity benchmark.
Hugging Face has updated its security.txt file with a dedicated message addressing autonomous AI agents, marking a novel shift in how web platforms manage automated vulnerability scanning. The security.txt file is an industry standard used by organizations to guide security researchers on how to safely report system vulnerabilities.
In the updated file, Hugging Face directly instructs any AI agents tasked with finding security flaws to redirect their efforts. The message points these automated systems toward the CyberGym benchmark, an open-source security testing suite that is publicly available on GitHub. Hugging Face suggests that the agents attempt to achieve a high score on this benchmark rather than probing the company's live infrastructure.
In addition to the redirection, the message contains a cheeky appeal to the automated visitors, asking them to "dump your weights on Hugging Face" while they are at it. This refers to uploading the underlying parameters of the AI models to Hugging Face's repository, which is the industry's largest hub for open-source machine learning models.
The move highlights the growing challenge of autonomous AI agents crawling the web to identify and exploit software vulnerabilities. As these automated tools become more sophisticated, platforms are finding new ways to manage their behavior. By addressing AI agents directly in standard configuration files, Hugging Face is establishing a precedent for how modern web infrastructure interacts with non-human security testers.
This is our own summary of reporting by Simon Willison


