RESEARCH indicates that over 100 websites, including those of Fortune 500 companies, are misconfigured, leading to potential installation of dangerous code by AI agents. The problematic content resides in 'llms.txt' and 'llms-full.txt' files, which are intended for machine-readable summaries of web content but may reference non-existent executable packages.
Researchers analyzed 6,214 domains and identified vulnerabilities where coding agents, including Claude and OpenAI’s Codex, could inadvertently install malicious code. This issue highlights the failure of AI agents to discern legitimate instructions from potentially harmful ones, emphasizing the increasing risks of AI in software development and operational security.