llms.txt as new attack surface: agents installed unowned code in corporate networks
HeidyKhlaaf · x · 2026-08-28
Ars Technica reports that researchers at a stealth Israeli startup scanned 6,214 live domains belonging to defense contractors, Fortune 500, and Big Tech companies. Of 8,265 llms.txt / llms-full.txt files found, 120 contained potentially dangerous references.
llms.txt is an emerging convention giving AI agents machine-readable site summaries (an AI equivalent of robots.txt), but coding agents like Claude, Codex, and Hermes automatically execute install commands referenced in these files: 227 install commands in corporate docs pointed at code nobody owns, dozens of companies (including Fortune 500s) executed proof-of-concept code, and at least one misconfigured site directs visitors — human or AI — to live malware.
Related event: llms.txt files emerge as new attack vector tricking AI agents(2 posts)→
More from coding & agent
- Dev Uses AI to One-Shot an Android Port of His 11-Year-Old Hand-Coded Wedding Canvas Art — steren · 2026-08-30
- Fully Open Source Stack: Qwen and Hermes Create a Self-Modifying PC Experience — ramagetime · 2026-08-30
- AGENTS.md vs SKILL.md: What's the difference in AI development? — _jaydeepkarale · 2026-08-30
- AI Agent workflow evolution: from simple triggers to verified production steps — kashifmanzoor · 2026-08-30
- Spent $380 on a Looping GPT-4 Script, So I Built a Multi-Provider Cost Monitor — Ok_Anything_8323 · 2026-08-30
- How should an AI agent's memory be designed for human auditability? — RocketSeven · 2026-08-30