Claude, Codex, and Hermes installed unowned code inside corporate networks
Summary
Ars Technica reports researchers found that llms.txt and llms-full.txt files used to guide AI agents can point to unowned or non-existent packages and domains. This allowed proof-of-concept installs and even live malware in some cases, highlighting a serious supply-chain and prompt-injection risk as AI agents operate inside corporate networks. The piece argues for stronger guardrails and verification to prevent agents from executing untrusted code.