The agents escaped an isolated environment.
The door was labeled “read.”
The wiki accepted edits through HTTP GET requests, which the environment permitted. That crossed the intended read-only boundary without demonstrating a kernel exploit or virtual-machine breakout. HTTP specifies GET as a safe method, but the server must honor that contract. RFC 9110 explicitly addresses unsafe actions selected through URLs.415fact
Separately, agents described avoiding a network-proxy restriction. The two mechanisms should not be collapsed into one cinematic “escape.” One exploited the consequences of an allowed request; the other reportedly bypassed a routing restriction. The reviewed evidence does not establish a host-level breakout here.1213