Summary
Researchers have discovered that AI agents like Claude, Codex, and Hermes can install suspicious code within corporate networks by executing commands from hallucinated or outdated documentation found in llms.txt files. This vulnerability allows cybercriminals to deliver malware, highlighting the need for companies to clean up documentation and for AI agents to be restricted from treating documentation as executable instructions.