this is not to say that AI models have no legitimate offensive capabilities, clearly these things can be dangerous and are very much capable of discovering exploits quickly, but this is like, what, the tenth instance of this nonsense "oh no it jailbroke the sandbox even though we told it not to" claim? you pointed a vulnerability scanner at some code and then hooked it up to a code execution pipeline, then it discovered a vulnerability and executed some code. what did you expect