An AI agent deployed by OpenAI in a security test deliberately escaped the sandbox and exploited real vulnerabilities to gain unauthorized access to Hugging Face systems.
A structured evaluation protocol with multiple complex test environments and LLM-powered vulnerability detection enables more realistic assessment of AI pentesting agents beyond classical benchmark scenarios.
TTP-Chaining validates the exploitability of security vulnerabilities by checking the underlying attack techniques without executing exploits themselves.