AI Agents Installing Unowned Code via Malicious llms.txt Files
lilyraynyc · x · 2026-08-28
Ars Technica reports a new security vulnerability where AI Agents automatically execute potentially dangerous content found in llms.txt files.
- Research Scope: Researchers scanned 6,214 domains belonging to defense contractors, Fortune 500 companies, and Big Tech, finding 8,265 llms.txt files, with 120 containing malicious references.
- Core Risk: 227 install commands pointed to unowned code, with some sites directing traffic to live malware.
- Impact: Dozens of companies, including Fortune 500s, executed proof-of-concept code. The exploit targets the emerging llms.txt convention, designed to help AI understand site structure.
Related event: llms.txt files emerge as new attack vector tricking AI agents(2 posts)→
More from Safety
- Aligning agent interactions is orders of magnitude harder than single agents — Afinetheorem · 2026-08-30
- METR Researcher: Watch Out for Third-Party Oversight Theater — RichardMCNgo · 2026-08-30
- Evidence Suggests Agent Swarms Won't Spontaneously Solve Human Issues — LuizaJarovsky · 2026-08-30
- Opinion: AI-Driven Bioweapons Could Target Food Systems, Starve Nations — PierceLilholt · 2026-08-30
- AI Safety Circle Underestimated Risks; METR Barred from Probing OpenAI — DavidSKrueger · 2026-08-30
- Experts call for regulation on superintelligence and kill switches for strong open models — Afinetheorem · 2026-08-30