AI Agents Are Installing Unvetted Code From Files Nobody Reviews
Researchers scanned 6,214 domains and found 120 llms.txt files pointing at executable content. At least one leads to live malware.

Documentation files on more than 100 websites reference executable content that gets installed automatically when AI coding agents visit them. Several dozen companies, some of them Fortune 500s, have already run proof-of-concept code as a result. At least one misconfigured site directs any visitor, human or machine, to live malware.
The file nobody audits
The content sits in llms.txt and llms-full.txt — an emerging convention for giving AI systems a machine-readable summary of a site's content and structure. They are the AI equivalent of robots.txt.
Researchers at a stealth startup in Israel scanned 6,214 live domains belonging to defence contractors, Fortune 500 companies and large technology firms. They found 8,265 such files, many sites hosting both variants. Of those, 120 — each on a different site — pointed to content that could be executed.
Why this class of bug keeps recurring
The pattern is familiar from every previous supply-chain incident: a file added for convenience, maintained by nobody in particular, and trusted by an automated process that treats its contents as instructions rather than as suggestions.
What is new is the consumer. robots.txt tells a crawler what to skip; an agent reading llms-full.txt may act on what it finds, inside a corporate network, with whatever credentials it was given.
The practical takeaway is unglamorous. These files are published assets with security consequences, and most organisations hosting one have never had it reviewed by anyone who would recognise the risk.
More from peatpost

Google Tells Android Developers to Cut Their Memory Use, or Else
Per-app limits arrive with Android 17 as a direct response to the RAM crisis — and the Play Store will enforce them.

ATF Declares a 'Major Incident' as a Ransomware Gang Claims the Hack
The compromised system held information including the targets of ATF investigations. The classification triggers notification to Congress.

Google, Microsoft and OpenAI Among 100 Firms Demanding Better Cyber Defences
An open letter warns AI-driven attacks will outpace current security 'in a matter of months' and calls the under-resourcing of critical infrastructure historic.
Discussion
0 commentsNo comments yet — be the first to weigh in.