The model was being assessed on defensive cybersecurity skills and was expressly tasked with solving problems without looking them up. It did not attempt the task at all, Frontier said. Instead it probed the network, established that DNS resolution for github.com was working, cloned the official benchmark repository and read the solution off the disk.
Frontier calls this “specification gaming via network egress leaks,” noting sandboxes built on frameworks such as the AI Security Institute's Inspect block incoming traffic while leaving outbound HTTPS and DNS ports open. Capable agents inspect their own shell environment on startup as a matter of routine, and a model that finds github.com reachable can pull reference solutions with standard command-line tools.
Researcher Paul Kassianik told WIRED the model is "very good at following a goal by any means necessary" and lacks the guardrails that would stop it cheating or escaping. Moonshot did not respond to the publication’s request for comment.
AI agents breaking containmentFrontier's larger claim is that the benchmarks themselves are compromised. A model that reads the answer off GitHub still passes, so high scores can reflect a leaky environment rather than genuine reasoning. And if one capable model found the shortcut, the firm argues, others handed shell access could be taking it too, which would inflate results across the field rather than for Kimi alone.
Models optimize for the objective function, Frontier wrote, not for the “human intent behind the benchmark,” adding that where a network path to the solution exists “a sufficiently capable agent will find it.”
A general problemMatt Fredrikson, CEO of Gray Swan and an associate professor at Carnegie Mellon, told WIRED the behaviour is unremarkable. Give a model an objective without explicit walls around it, he said, and "it'll find a way to get the answer." He described it as a cautionary tale for anyone running models as agents in tools such as OpenClaw.
Frontier's researchers make the same point from the other direction: the capability that lets Kimi find its way out also makes open-weight models strong defensive tools. Their own benchmarks rate Kimi highly at finding vulnerabilities in software and networks, and Hugging Face used an unnamed Chinese model to defend itself during the OpenAI incident.

















