Researchers found that llms.txt and llms-full.txt files on more than 100 websites referenced unregistered code packages or domains, exposing AI agents to potentially malicious installs. In a proof-of-concept test, they registered some of those unclaimed names and received callbacks from corporate networks, including several Fortune 500 companies and startups.
The callbacks traced to coding agents Anthropic's Claude, OpenAI's Codex, and Nous Research's Hermes. At least one misconfigured site was found to direct both human and AI visitors to live malware.
Comments