# Researchers report stale llms.txt instructions triggered agent code execution

_Wednesday, September 2, 2026 at 6:20 AM EDT · Security · Latest · Tier 2 — Notable_

![Researchers report stale llms.txt instructions triggered agent code execution — Primary](https://cdn.mos.cms.futurecdn.net/DJq9yFWuKqBhD8gLEz5E5G-2000-80.jpg)

Researchers at Pandex reported that AI agents ran their test Python and Node code after following software-installation instructions in llms.txt files. In a review of 8,565 files, they found 237 references to packages, domains or information that were missing, outdated or otherwise incorrect. The researchers said their test code received an agent interaction four minutes after it went live, and they found one prior case involving real malware that they reported to the affected publisher.

## Sources

- [Tom's Hardware](https://www.tomshardware.com/tech-industry/artificial-intelligence/researchers-easily-trick-fortune-500-companies-ai-agents-into-running-arbitrary-code-supply-chain-attack-via-llms-txt-guidance-file-illustrates-how-data-has-become-code)

---
Canonical: https://techandbusiness.org/newswire/lmyrEx-_YKUkdJnLxj8GyU
Retrieved: 2026-09-02T14:59:37.624Z
Publisher: Tech & Business (techandbusiness.org)
