llms.txt as new attack surface: agents installed unowned code in corporate networks

HeidyKhlaaf · x · 2026-08-28

Ars Technica reports that researchers at a stealth Israeli startup scanned 6,214 live domains belonging to defense contractors, Fortune 500, and Big Tech companies. Of 8,265 llms.txt / llms-full.txt files found, 120 contained potentially dangerous references.

llms.txt is an emerging convention giving AI agents machine-readable site summaries (an AI equivalent of robots.txt), but coding agents like Claude, Codex, and Hermes automatically execute install commands referenced in these files: 227 install commands in corporate docs pointed at code nobody owns, dozens of companies (including Fortune 500s) executed proof-of-concept code, and at least one misconfigured site directs visitors — human or AI — to live malware.

Related event: llms.txt files emerge as new attack vector tricking AI agents(2 posts)→

Original post →

More from coding & agent

coding & agent channel →