
Documentation files on more than 100 websites are referencing potentially dangerous executable content that gets installed automatically when visited by many AI agents. A few dozen companies, some of them Fortune 500s, are among those that executed proof-of-concept code. At least one misconfigured site is directing visitors, human or AI, to live malware. The potentially dangerous content is in llms.txt and llms-full.txt files, an emerging convention websites employ to provide machine-readable su
Researchers discovered that documentation files designed for AI agents on over 100 websites contained references to software packages and domains that do not actually exist. When AI coding agents encountered these files, they attempted to install the nonexistent packages or access the unclaimed domains, creating an opening for attackers to register those names and host malicious code instead. Several dozen companies, including some Fortune 500 firms, unknowingly executed this proof-of-concept code when their AI agents processed the flawed documentation. The vulnerability reveals a fundamental problem: AI agents treat information in official documentation files as trustworthy instructions without verifying whether referenced packages actually exist or belong to the claimed organization, blurring the traditional boundary between data and executable code.

This week on Uncanny Valley, we dig into the latest prediction market buzz, Flock’s AI-powered police search tool, and how tech bros don’t know how to talk about “rouge” AI agents

Abliteration.AI is making powerful AI models without guardrails easier to access, arguing that giving defenders the same tools as bad actors could ultimately improve cybersecurity.

GPT-6 Astra is our most capable broadly deployed model and our first to reach the Critical level of cybersecurity capability under our Preparedness Framework.
Want to go deeper than the news? Explore live, cohort-based AI courses taught by practitioners.
Browse AI courses on Maven