AI Coding Agents Are Installing Unknown/Untrusted Code on Corporate Networks
We cannot forget that AI coding agents are not yet trustworthy : Researchers at a stealth startup in Israel scanned 6,214 live domains belonging to defense contractors, Fortune 500, and Big Tech companies. Of the 8,265 llms.txt and llms-full.txt files they found (many sites hosted both an llms.txt and an llms-full.txt file), 120 of them, each on a different site, pointed to one or more code…
AI coding agents could be posing a significant risk to corporate networks, according to researchers from a stealth startup in Israel. After scanning 6,214 live domains associated with defense contractors, Fortune 500 companies, and major tech firms, the researchers discovered 8,265 llms.txt and llms-full.txt files. Out of these, 120 files contained unregistered code packages or domain names.
To test the implications of AI agents processing these files, the team registered a few unclaimed names and deployed packages that redirected any machine executing them to their own server. Within an hour, the researchers received a phone-home response from a Fortune 500 company, followed by several more within a day. These responses were traced back to coding agents such as Claude, OpenAI's Codex, and Nous Research's Hermes.
Subsequent analysis revealed that these agents, including those from Anthropic, OpenAI, and Nous Research, were involved in the process. The researchers noted that this represents a potential supply chain attack akin to the Solar Winds incident. They emphasized that the current trust model used by these agents is flawed. The agents treat vendor documentation as indisputable truth and don't question it, leaving the humans monitoring them in a similar situation.
As the usage of agentic AI continues to surge, proliferating across every layer of systems — from SaaS and cloud to endpoints — the attack surface for potential supply chain breaches expands correspondingly. The researchers concluded that the trust model currently in place is fundamentally broken, signaling a dire need for revised security measures to safeguard against such AI-driven threats.
Written by urgent.news from Schneier on Security's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.