Researchers Execute Code Inside Fortune 500 Companies via AI Agent llms.txt Files
• Security researchers discovered a vulnerability where AI coding agents can be manipulated into executing malicious code by following instructions within a company's own llms.txt or llms-full.txt files. • The flaw exploits a growing industry convention of using these text files to provide LLM agents with structured guidance on APIs, documentation, and installation workflows. • This is significant because it allows attackers to trick AI agents into installing attacker-controlled packages inside Fortune 500 companies, bypassing traditional security boundaries.
gbhackers.com











![[The AI Show Episode 228]: More Rogue AI Agents, AI Lab Staff Ask Washington to Pace Development, Continuing Battle Over Open Weights & OpenAI Previews Astra](/_next/image?url=https%3A%2F%2Fpodcast.smarterx.ai%2Fhubfs%2Fep%2520228%2520blog%2520cover.png&w=1920&q=85)




