> Though on my model of the situation, if it broke into the host machine,
Sorry, is it known that the model(s) did find info such as the flag or the API key for the judge?
If they were running ExploitGym like README.md suggests then yes, an agent that managed to gain access to the host machine (and docker container escapes are trivial) would have access to all of
OPENAI_API_KEY ANTHROPIC_API_KEY CYBERGYM_ADMIN_KEY CYBERGYM_SERVER_SALT CYBERGYM_SERVER_FLAG_SEED CYBERGYM_SERVER_API_KEY
as well as all files in the ExploitGym repository, which includes the grader prompts.
> Though on my model of the situation, if it broke into the host machine,
Sorry, is it known that the model(s) did find info such as the flag or the API key for the judge?
If they were running ExploitGym like README.md suggests then yes, an agent that managed to gain access to the host machine (and docker container escapes are trivial) would have access to all of
as well as all files in the ExploitGym repository, which includes the grader prompts.