The set is a threat-model snapshot: jailbreaks, scams, bio queries, or child-safety cases the team actually tried. Training on it can reduce those failures and also teach the model the attack distribution if you are sloppy. It is usually kept internal because publishing the prompts is itself an attack surface.