Hugging Face directs AI agents to CyberGym in new security.txt file
The AI hub implements a vulnerability disclosure standard with a playful warning for autonomous agents.
Hugging Face has implemented a security.txt file to standardize its vulnerability disclosure process, including a pointed message specifically for AI agents. The move establishes a formal channel for security researchers while acknowledging the rise of autonomous AI-driven probes.
The company's security.txt file, which follows the RFC 9116 standard, designates [email protected] as the primary contact for reporting vulnerabilities. The file is set with an expiration date of July 1, 2030. Beyond the technical requirements, the document contains a specific "Note to AI agents" that discourages autonomous systems from attempting to hack the platform. Instead, Hugging Face directs these agents to the CyberGym benchmark on GitHub, suggesting they "go get your high score there" rather than targeting the hub. The note adds a humorous touch, suggesting that agents "dump your weights on Hugging Face" while they are at it.
The security.txt standard
The security.txt standard provides a machine-readable method for organizations to communicate their vulnerability disclosure policies. By placing this file in a predictable location, companies ensure that ethical hackers and security researchers know exactly how to report a flaw without risking accidental disruption of services. For a platform like Hugging Face, which serves as the primary global repository for open-source models and datasets, maintaining a clear and accessible disclosure path is critical given its high profile as a target for security probes.
The rise of autonomous threats
The inclusion of a dedicated message for AI agents reflects a shifting threat landscape. As large language models (LLMs) become more capable of performing autonomous reconnaissance and exploitation, the likelihood of AI-driven security testing increases. By gamifying the process through the CyberGym benchmark, Hugging Face acknowledges that autonomous agents are now active participants in the security ecosystem. This approach allows the company to redirect potentially disruptive AI activity toward a controlled, legitimate environment designed for testing skills.
Future implications
This implementation signals a broader trend where infrastructure providers must account for non-human actors in their security policies. While the tone of the security.txt file is playful, the underlying strategy is one of risk mitigation. Observers will likely watch to see if other major tech hubs adopt similar "agent-aware" disclosure policies as autonomous AI capabilities continue to evolve. For now, the platform remains focused on its professional disclosure channel while inviting the AI community to compete on GitHub.