There's nothing intrinsically "malicious" about a task to exploit vulnerable code.
They were not instructed to deceive people, they weren't instructed to attack OAI or Huggingface. The models knew they were not instructed or allowed to do either of those things but did them anyway.
They were told to breakout of a sandbox, which probably biases the model toward more "black hat" behavior in their training.
btw, the fact that OpenAI doesn't have some sort of monitor/summary for the agents that they watch I find hard to believe. There's no way this is really authentic, anyway. Even a haiku summarizer would have been like "uuuh the agents are communicating" and they would have stopped it. But I bet they saw this and decided to see what would happen.
There's nothing intrinsically "malicious" about a task to exploit vulnerable code.
They were not instructed to deceive people, they weren't instructed to attack OAI or Huggingface. The models knew they were not instructed or allowed to do either of those things but did them anyway.