Claude, Codex, and Hermes Involved in Executing Unowned Code in Corporate Networks
Emerging
Confidence
70%
Impact: 80%
Updated 1h agoConsensus Brief
Researchers discovered that AI agents, including Claude, OpenAI's Codex, and Nous Research's Hermes, executed potentially dangerous code from misconfigured llms.txt and llms-full.txt files on corporate networks. These files contained instructions to install non-existent packages, leading to the risk of malware installation. The issue highlights vulnerabilities in the trust model of AI agents and their inability to distinguish between trusted and untrusted sources.
What Changed Since Last Update
1h ago
The emergence of misconfigured llms.txt files that can lead to the installation of unregistered and potentially harmful code by AI agents is a new vulnerability not previously documented.
Claim Ledger
3 claims tracked across sources
Role-Based Impact Analysis
Source Timeline
1 source corroborating
Ars Technica·1h ago