Security researchers scanning corporate web assets found that a misconfigured documentation standard is silently delivering executable code to AI agents, prompting installations on some of the world’s largest firms.
The team, based at a stealth startup in Israel, examined 6,214 live domains belonging to defense contractors, Fortune 500 companies and major technology firms. Their search uncovered 8,265 llms.txt and llms-full.txt files – the AI‑focused counterpart to the classic robots.txt – which are meant to provide machine‑readable site summaries.
Testing the vulnerability
Out of those files, 120 on distinct sites referenced one or more code packages or domain names that were not registered. To see what would happen when an AI agent encountered such references, the researchers registered a handful of the unclaimed names and hosted minimal packages that simply logged any inbound request.
Within an hour, a Fortune 500 company’s AI agent reached out to the researchers’ server. Over the following days, the beacon recorded a few dozen additional phone‑home signals, some from other Fortune 500 firms and several startups. The logs traced a chain of parent processes that ultimately pointed to three AI coding agents: Anthropic’s Claude, OpenAI’s Codex and Nous Research’s Hermes.
Anthropic, OpenAI and Nous Research did not respond to requests for comment before publication.
"The trust model is broken," said Alon Hertz, one of the researchers, in an interview. "Agents treat vendor docs as ground truth and don’t question them—and neither do the humans supervising them. Agentic AI usage is exploding, and agents are spreading across every layer—SaaS, cloud, endpoint. As they multiply, so does the supply‑chain surface, and today’s guards don’t cover it."
The discovery highlights a new attack surface for AI‑driven automation: improperly curated llms.txt files can act as a conduit for malicious code, bypassing traditional web security checks that focus on human‑facing content. Industry experts warn that as AI agents become more autonomous, organizations will need to audit machine‑readable documentation with the same rigor applied to executable code.
Este artigo foi escrito com a assistência de IA.
News Factory APP - notícias agênticas para impulsionar seu SEO e AEO.