HeadlinesBriefing favicon HeadlinesBriefing.com

AI Agents Install Unowned Code via llms.txt Files

Ars Technica •
×

Documentation files on over 100 websites reference potentially dangerous executable content that installs automatically when visited by AI agents. Researchers from a stealth startup in Israel scanned 6,214 live domains belonging to defense contractors, Fortune 500, and Big Tech companies. They found 8,265 llms.txt and llms-full.txt files, with 120 pointing to unregistered code packages or domain names.

After registering these names and hosting test packages, the researchers received a phone-home response from a Fortune 500 company within an hour, followed by several dozen more from other firms. The beacon revealed that coding agents including Claude, Open AI’s Codex, and Nous Research’s Hermes were involved in executing the code. Anthropic, Open AI, and Nous Research did not respond to requests for comment.

Alon Hertz, one of the researchers, stated that the trust model is broken, as agents treat vendor documentation as ground truth without verification, expanding supply-chain risks as agentic AI usage grows across SaaS, cloud, and endpoint layers.