Keyboard shortcuts

Aug 27, 2026, 07:34 PM UTC
Technology // Security

AI Agents Are Installing Unvetted Code From Files Nobody Reviews

Researchers scanned 6,214 domains and found 120 llms.txt files pointing at executable content. At least one leads to live malware.

peatpost Desk
Aggregated
Aug 27, 2026, 02:00 PM UTC2 min read
AI Agents Are Installing Unvetted Code From Files Nobody Reviews
SourceArs Technica· 5h ago

Documentation files on more than 100 websites reference executable content that gets installed automatically when AI coding agents visit them. Several dozen companies, some of them Fortune 500s, have already run proof-of-concept code as a result. At least one misconfigured site directs any visitor, human or machine, to live malware.

The file nobody audits

The content sits in llms.txt and llms-full.txt — an emerging convention for giving AI systems a machine-readable summary of a site's content and structure. They are the AI equivalent of robots.txt.

Researchers at a stealth startup in Israel scanned 6,214 live domains belonging to defence contractors, Fortune 500 companies and large technology firms. They found 8,265 such files, many sites hosting both variants. Of those, 120 — each on a different site — pointed to content that could be executed.

Why this class of bug keeps recurring

The pattern is familiar from every previous supply-chain incident: a file added for convenience, maintained by nobody in particular, and trusted by an automated process that treats its contents as instructions rather than as suggestions.

What is new is the consumer. robots.txt tells a crawler what to skip; an agent reading llms-full.txt may act on what it finds, inside a corporate network, with whatever credentials it was given.

The practical takeaway is unglamorous. These files are published assets with security consequences, and most organisations hosting one have never had it reviewed by anyone who would recognise the risk.

Written by
peatpost Desk
Aggregated · @peatpost
Share

Discussion

0 comments
0/2000

No comments yet — be the first to weigh in.

More from peatpost