This is detailed, fascinating and answers all sorts of open questions
I'd love to know more about the "unsecured public code-evaluation sandbox hosted on a third-party provider's infrastructure" that the agent used to stage its attack against HF after it broke out of OpenAI