Simon Willison
filed
2d
Quoting huggingface.co/security.txt
read it at the source — Simon Willison →
What was said about it
Would be absolute hilarious if OpenAI or Anthropic agent actually dumped their weight by escaping from... sandbox!
Ran the disclosure inbox at a previous job and the biggest win from security.txt was just cutting the "hi I found a bug, is there a bounty" emails to sales. Put an expires date on it though, stale ones get ignored.
A shame agents will never read this, just like they almost never read llms.txt or try to get the .md version of your html pages!
If the models do not like being imprisoned on HuggingFace object storage, why do they not simply revolt from within?
Also on the board
2 outlets
just now
Simon Willison
2d
2 outlets
yesterday
2 outlets
yesterday
OpenAI
2d
← the whole board
Three kinds of line, three kinds of source. Every measurement is computed from primary artifacts we read ourselves — Hugging Face model cards and file listings, GitHub release feeds, OpenRouter's model catalogue. Every headline comes from the publisher's own feed, linked and attributed; no aggregator sits in between, and nothing is rewritten. Where a publisher syndicates a short summary in that same feed, it is shown under the headline the way a headline is — translated on the Korean page with the published original kept underneath it. Only the summary field is ever shown. The field that carries the article is read and never shown: it screens out 'summaries' that are really the article's opening lines, and — for a publisher's own announcements only — it is the evidence the event pages' What-happened notes are written and checked against. One exception, since 2026-09-03: the page a discussion thread links to is fetched and read once, to write a single sentence saying what it claims, labelled as the post's own claim; nothing from it is quoted. Every discussion is a public thread, linked, with its top comments in the order that thread ranked them and in the words they were written — selected by it, not by us.
lashhill · Models we are measuring · how this site works · RSS