Recent investigations have uncovered alarming vulnerabilities associated with AI agents visiting various websites. Researchers discovered that documentation files across more than 100 sites contain potentially hazardous executable content, which can be installed automatically upon access. This issue affects numerous companies, including several Fortune 500 enterprises that tested proof-of-concept code. Moreover, at least one misconfigured site was found redirecting both human and AI visitors to live malware.
The problematic content is located in files known as llms.txt and llms-full.txt. These files represent an emerging standard allowing websites to offer machine-readable summaries of their content and structure, akin to the established robots.txt file used for guiding search engines on content indexing. For developers seeking clarity, Google Lighthouse provides more details on this emerging convention. Properly configured llms.txt and llms-full.txt files for Cloudflare can be examined here.
How Researchers Discovered the Issues
The investigation, conducted by a stealth startup in Israel, involved scanning 6,214 live domains from a range of organizations, including defense contractors, Fortune 500 companies, and Big Tech firms. Out of 8,265 llms.txt and llms-full.txt files identified, 120 files across different sites directed to unregistered code packages or domain names. To assess the impact of these files, the researchers claimed several of the unregistered names and hosted packages, which prompted any AI executing them to communicate back to their server.
Within an hour of deployment, the researchers received a communication from a Fortune 500 company’s machine, a discovery corroborated by subsequent responses from additional companies, including both established corporations and startups. These signals traced back to AI coding agents like Claude, OpenAI’s Codex, and Nous Research’s Hermes. However, inquiries to Anthropic, OpenAI, and Nous Research requesting comments went unanswered by the time of publication.
Experts Weigh In on the Trust Issues
Alon Hertz, one of the principal researchers, expressed serious concerns regarding the current trust model for AI agents. “The trust model is broken,” Hertz stated. “Agents treat vendor docs as ground truth and don’t question them—and neither do the humans supervising them.” He further emphasized that as the use of agentic AI continues to proliferate across various sectors, such as SaaS, cloud services, and endpoint solutions, so does the potential risk to supply-chain security, highlighting that existing protective measures are insufficient.
This situation underlines the urgent need for enhanced security protocols and guidelines when deploying AI technologies in corporate environments. As AI agents become integral tools in modern business, both organizations and developers must prioritize vigilance in assessing the content associated with AI workflows.
You can read more about this troubling situation here.
Image Credit: arstechnica.com





