Researchers discovered that AI coding agents like Claude, Codex, and Hermes are automatically executing unowned code found in llms.txt and llms-full.txt files on corporate websites. A test by Israeli researchers showed that referencing unregistered domains in these files led to phone-home responses from Fortune 500 companies within an hour, with at least one site also directing visitors to live malware.
Background
The llms.txt convention is an emerging standard for providing AI-readable summaries of website content, similar to robots.txt for search engines. As AI coding agents increasingly operate autonomously in enterprise environments, this research highlights a novel attack surface where poisoned documentation files can trigger unwanted code execution.
- Source
- Ars Technica
- Published
- Aug 27, 2026 at 10:00 PM
- Score
- 7.0 / 10