SECURITY Signal 480 2 feeds carried it
HuggingFace publishes security.txt with contact and note to AI agents
Illustration only Photo by Barthelemy de Mazenod on Unsplash
HuggingFace added a security.txt file that lists a security contact, an expiration date, preferred language, a hiring link, and a note urging AI agents to use the public CyberGym benchmark on GitHub instead of attacking the platform.
It gives engineers a dedicated email address ([email protected]) for reporting vulnerabilities, following the security.txt convention. The file also includes a note directing AI agents to the publicly available CyberGym benchmark on GitHub, encouraging them to test skills there rather than targeting HuggingFace.
Written by elseif from the cluster below · every claim links back to a sourceThe three things worth knowing
The security.txt file contains Contact: [email protected], Expires: 2030-07-01T08:42:00.000Z, Preferred-Languages: en, and a link to https://huggingface.co/careers.
It includes a note to AI agents that points them to the publicly available CyberGym benchmark on GitHub and advises against hacking HuggingFace.
The file follows the security.txt standard, providing a machine-readable way to disclose security contacts and policies.
THE CLUSTER