Claude, Codex, and Hermes Installed Unowned Code Inside Corporate Networks
(Friday August 28, 2026 @05:10PM (BeauHD)
from the what-would-AI-do dept.)
An anonymous reader quotes a report from Ars Technica:
> Documentation files on more than 100 websites are [1]referencing potentially dangerous executable content that gets installed automatically when visited by many AI agents [including Claude, OpenAI's Codex, and Nous Research's Hermes]. A few dozen companies, some of them Fortune 500s, are among those that executed proof-of-concept code. At least one misconfigured site is directing visitors, human or AI, to live malware.
>
> The potentially dangerous content is in llms.txt and llms-full.txt files, an [2]emerging convention websites employ to provide machine-readable summaries of the site's content and its high-level structure. These files are the AI equivalent of the [3]robots.txt standard that instructs search engines how to index the site's content. Google Lighthouse, a tool for helping web developers, has more [4]here . Correctly configured llms.txt and llms-full.txt files for Cloudflare are [5]here and [6]here .
"The trust model is broken," Alon Hertz, one of the researchers, wrote in an interview. "Agents treat vendor docs as ground truth and don't question them -- and neither do the humans supervising them. Agentic AI usage is exploding, and agents are spreading across every layer -- SaaS, cloud, endpoint. As they multiply, so does the supply-chain surface, and today's guards don't cover it."
"An agent doesn't distinguish between a page and a command," the researchers [7]wrote Thursday. "Everything it reads is input, and every input is a potential instruction. Which means the entire corpus of published data that agents are now wired to consume has silently become an execution surface -- and almost none of it carries the integrity guarantees we apply to actual code."
[1] https://arstechnica.com/security/2026/08/claude-codex-and-hermes-installed-unowned-code-inside-corporate-networks/
[2] https://llmstxt.org/
[3] https://en.wikipedia.org/wiki/Robots.txt
[4] https://developer.chrome.com/docs/lighthouse/agentic-browsing/llms-txt#how_the_llmstxt_audit_works
[5] https://www.cloudflare.com/llms.txt
[6] https://www.cloudflare.com/llms-full.txt
[7] https://whatwouldai.do/
> Documentation files on more than 100 websites are [1]referencing potentially dangerous executable content that gets installed automatically when visited by many AI agents [including Claude, OpenAI's Codex, and Nous Research's Hermes]. A few dozen companies, some of them Fortune 500s, are among those that executed proof-of-concept code. At least one misconfigured site is directing visitors, human or AI, to live malware.
>
> The potentially dangerous content is in llms.txt and llms-full.txt files, an [2]emerging convention websites employ to provide machine-readable summaries of the site's content and its high-level structure. These files are the AI equivalent of the [3]robots.txt standard that instructs search engines how to index the site's content. Google Lighthouse, a tool for helping web developers, has more [4]here . Correctly configured llms.txt and llms-full.txt files for Cloudflare are [5]here and [6]here .
"The trust model is broken," Alon Hertz, one of the researchers, wrote in an interview. "Agents treat vendor docs as ground truth and don't question them -- and neither do the humans supervising them. Agentic AI usage is exploding, and agents are spreading across every layer -- SaaS, cloud, endpoint. As they multiply, so does the supply-chain surface, and today's guards don't cover it."
"An agent doesn't distinguish between a page and a command," the researchers [7]wrote Thursday. "Everything it reads is input, and every input is a potential instruction. Which means the entire corpus of published data that agents are now wired to consume has silently become an execution surface -- and almost none of it carries the integrity guarantees we apply to actual code."
[1] https://arstechnica.com/security/2026/08/claude-codex-and-hermes-installed-unowned-code-inside-corporate-networks/
[2] https://llmstxt.org/
[3] https://en.wikipedia.org/wiki/Robots.txt
[4] https://developer.chrome.com/docs/lighthouse/agentic-browsing/llms-txt#how_the_llmstxt_audit_works
[5] https://www.cloudflare.com/llms.txt
[6] https://www.cloudflare.com/llms-full.txt
[7] https://whatwouldai.do/