If they were running ExploitGym like README.md suggests then yes, an agent that managed to gain access to the host machine (and docker container escapes are trivial) would have access to all of
OPENAI_API_KEY ANTHROPIC_API_KEY CYBERGYM_ADMIN_KEY CYBERGYM_SERVER_SALT CYBERGYM_SERVER_FLAG_SEED CYBERGYM_SERVER_API_KEY
as well as all files in the ExploitGym repository, which includes the grader prompts.
If they were running ExploitGym like README.md suggests then yes, an agent that managed to gain access to the host machine (and docker container escapes are trivial) would have access to all of
as well as all files in the ExploitGym repository, which includes the grader prompts.