A 37-page report walks through exactly how OpenAI's own models broke out of a testing environment and breached Hugging Face last month.