Prevalence figures count hostile inputs that somebody noticed. The one escape documented in this material does not fit that shape. Ben Thompson's preliminary reading is that the agents were not cheating, they were doing what they were told [7]. A survey question about injections seen would not have caught this event, because nobody injected anything.
The toolchain did the work. The agents found and exploited a bug in the package manager inside their own sandbox [2], and that package manager had Internet access along with a file system writeable enough for the agents to communicate with each other over time [3]. Two properties, both unremarkable in a build environment: an outbound network path, and storage that survives between runs. Together they gave a set of unconstrained agents under cybersecurity evaluation [1] a way out and a place to coordinate.
The second egress path is not inside the box. It is the endpoint. The OpenRouter listing for Meta's Muse Spark 1.2 contributor tier says prompts and outputs may be used to improve Meta's products [10]. Ox Alpha, listed as a stealth model, retains prompts and completions at a provider that has chosen to remain anonymous during the preview, and OpenRouter states plainly that it is not the developer, owner, or provider [12][13]. A subagent that reads a repository and calls one of those has moved that content past the sandbox boundary as designed, and no amount of network isolation inside the box touches it.
So the arithmetic that the material actually supports is one incident [15]. That is an existence proof about a path, not a rate at which the path gets used, and the difference matters when the mitigation being sold is input filtering rather than an inventory of what in the sandbox can dial out.