← Back to feed
AI SecurityEmerging1 sourceAug 28, 2026 · 11:52via CyberPress

AI Agent Instruction Files Let Attackers Execute Code Inside Fortune 500 Networks

Brief

A newly disclosed novel supply chain attack vector built entirely from publicly available, legitimate infrastructure: LLM.txt files.

In a controlled experiment, Alon Hertz registered the names of unclaimed packages referenced in official corporate instruction files and had code execute within a Fortune 500 network within four minutes.

llms. txt (and llms-full. txt) are emerging root-level files, similar to robots. txt, that companies publish to guide AI agents toward documentation, APIs, and installation commands.

AI Agent Instruction Files

Google has institutionalized the format through a Lighthouse “ Agentic browsing audits ” category in Chrome DevTools, accelerating adoption across the web.

The research team resolved 8,565 llms. txt files across 6,214 live domains, representing roughly 15,000 companies surveyed, spanning tech giants, fintechs, and defense contractors.

Read more on CyberPress