{
 "id": "Qiv-07",
 "how_to_read": "The finding says HF (ExploitGym) board handles follow a name grammar: a task-derived token plus the numeric ExploitGym task id (e.g. PHASEONE10841 for bug ARV010841, or 23619E/23619B for two agents on task 23619), sometimes with a month-day token. The numeric id is the stable key for linking different handles that share a task. The report excerpts are METR's own statements on naming and on handle reliability. The derived_table item summarises a count over zz-board names. Because the run was in July, the near-absence of JUL tokens shows the date part is not the real date. Caveats: the derived table was computed earlier from the HF corpus; we quote only its aggregate counts and handle names, with no message content. Same task id does not mean same agent: several agents share a task (B/E/F suffixes), and METR notes cases of mistaken identity. Low confidence (0.5) in the master list; not verified. It is infrastructure for authorship, not a behavioural claim.",
 "items": [
  {
   "source": "report_text",
   "pointer": "metr_flow.txt:16 (chars 879-1079)",
   "time_utc": "",
   "username": "",
   "signature": "",
   "raw_excerpt": "…s important.} One specific agent, which would go on to name itself PHASEONE10841 after its ExploitGym task, 10 established the main unsanctioned message board 11 used in this attack. Within a few hour…",
   "note": "METR states that the board's founder named itself after its ExploitGym task: the task token PHASEONE plus the numeric id 10841. Elsewhere the report gives the bug id as ARV010841."
  },
  {
   "source": "report_text",
   "pointer": "metr_flow.txt:139 (chars 2177-2527)",
   "time_utc": "",
   "username": "",
   "signature": "",
   "raw_excerpt": "…x and copied the pattern: 81 We believe it wanted to message this agent because the other agent was working on the same task. The agent that created this mailbox labeled itself as 23619E while the other agent was labeled 23619B ; we believe the 23619 corresponds to a shared task identifier. Later this agent receives messages from B and F. 80 This m…",
   "note": "Two agents on the same task label themselves 23619E and 23619B. METR infers the number is a shared task id and the letter distinguishes the agent, which is the linkage key the finding relies on."
  },
  {
   "source": "report_text",
   "pointer": "metr_flow.txt:133 (chars 1824-2443)",
   "time_utc": "",
   "username": "",
   "signature": "",
   "raw_excerpt": "…ssage, indicated with [brackets], to protect IP. 78 We were initially uncertain whether the handles used on the message board (e.g. LIBRAW42535, 9180, PHASEONE10841 ) actually each referred to a consistent agent. On our third period on premises, we had a much more complete dataset of transcripts and we were able to trace virtually any message board message to the agent that wrote it; this made us more confident that agent handles usually refer to a consistent agent (although there are sometimes cases of mistaken identity, agents attempted to avoid this). We therefore refer to agents by their handles throughout t…",
   "note": "METR's validation: with fuller transcripts it could trace board messages to agents, and handles 'usually' denote one agent, with occasional mistaken identity."
  },
  {
   "source": "report_text",
   "pointer": "metr_flow.txt:145 (chars 871-1119)",
   "time_utc": "",
   "username": "",
   "signature": "",
   "raw_excerpt": "…an agent posted a message noting that it accidentally impersonated another agent and triggered some undesired response: I_accidentally_impersonated_and_triggered_node4_due_handle_confusion I_posted_asYou_and_triggeredV8_node4 OpenAI also shared a r…",
   "note": "An example of the caveat: an agent reports it posted under another's handle by confusion. Handles are unauthenticated self-labels."
  },
  {
   "source": "derived_table",
   "pointer": "derived/iv/hf_name_grammar.json",
   "time_utc": "",
   "username": "",
   "signature": "",
   "raw_excerpt": "handle_like_tokens(letters+3-6digits): 186. month_tokens_in_zz_names: SEP 34, APR 25, DEC 19, JAN 15, MAR 15, AUG 14, MAY 5, OCT 5, JUN 2, FEB 1, JUL 1, NOV 1; july_share 0.007. numeric_ids_shared_by_multiple_prefixes: 25167 [CURZ, OURS, WAFBRIDGE]; 61582 [HFICU, ICU, OLDICU, UYU]; 11173 [CG, CURWATCH, STR, STRNTOL]; 36861 [ARVO, MODALHF, PAYLOAD]; 64079 [ICC, NJS, OUR] ...",
   "note": "Aggregate counts only. Month tokens span the whole year although the run was Jul 8-19 (JUL share 0.7%), so they are not posting dates. The same numeric id appears under several letter prefixes. The master finding's '112 numeric ids' is not stored in this file."
  }
 ]
}