More than 100 websites carried llms.txt or llms-full.txt files that directed AI agents to unregistered code packages, researchers found. After registering some of those unclaimed addresses, the researchers recorded callbacks from dozens of organizations, including Fortune 500 companies, with execution traces showing Claude, OpenAI Codex, and Hermes had installed the proof-of-concept code.
The findings highlight how AI coding agents can automatically execute content referenced in machine-readable site summaries. At least one misconfigured site was also directing visitors, both human and AI, to live malware.
Comments