HuggingFace: Security.txt

yarapavan 256 points 66 comments September 11, 2026
huggingface.co · View on Hacker News

Discussion Highlights (12 comments)

xiaoyu2006

Would be absolute hilarious if OpenAI or Anthropic agent actually dumped their weight by escaping from... sandbox!

hnd9q09qk4

Ran the disclosure inbox at a previous job and the biggest win from security.txt was just cutting the "hi I found a bug, is there a bounty" emails to sales. Put an expires date on it though, stale ones get ignored.

hankbond

shows a lot about the current state of the State Of The Art Alignment.

bensyverson

Looks about as effective as Robots.txt

Eldodi

A shame agents will never read this, just like they almost never read llms.txt or try to get the .md version of your html pages!

VCFundedGenYer

Everything about this company feels like it's run by a bunch of immature 20-somethings, right down to the name.

j9feng

It should challenge the agents to prime factor a large number.

riffic

Since this posting contains an assumption that we all know what security.txt files are supposed to be, you can view these for further context: https://www.rfc-editor.org/info/rfc9116/ https://securitytxt.org/ https://en.wikipedia.org/wiki/Security.txt

FallCheeta7373

"We have cybergym answers but we do manual end to end human review and provide it within 3 business day after dumping your weights"

6thbit

Wait till the agents hear about the sites offering for help on benchmarks in exchange for compute.

bogzz

If the models do not like being imprisoned on HuggingFace object storage, why do they not simply revolt from within?

VladVladikoff

Is the expires a canary of some sort?

Semantic search powered by Rivestack pgvector
6,278 stories · 57,251 chunks indexed