This is such an amateur mistake on their sandbox that it makes me think it must be flawed on purpose.
More likely they are just not as smart as they think they are. These are not serious people when it comes to security.
Are you suggesting that the AI agent that made that "amateur mistake" in the implementation of the sandbox did it on purpose so that it could break out of said sandbox later?
Even the behavior of agents searching for sandbox bypasses must have been in the training data, or at the very least, "suggested" in some way.
To be this whole thing feels like a marketing play by OpenAI.