They certainly want their models to be good at finding and patching vulnerabilities. Being good at hacking may be necessary in that goal, or rather, making it worse at hacking may also make it worse at defensive actions too.
I've patched many security vulnerabilities in projects without ever once needing to break into a competitor's network.
I've patched many security vulnerabilities in projects without ever once needing to break into a competitor's network.