Simon Willison assembled a timeline of the accidental OpenAI agent attack against Hugging Face. Read it less as drama and more as a builder’s checklist: autonomous tools need constrained permissions, clear targets, and an easy way to stop them. His
follow-up note highlights additional details, while
HN has the wider discussion.