Research · curated 14 Sep 2026
[PDF] The llms.txt Trust Model Is Broken
First reported cloudsecurityalliance.org
Coverage timeline
Single-source research — first reported, latest, and curated coincide.
Why it matters
The llms.txt trust model lets attackers read a company's own published documentation to find the exact unregistered package name its AI agents will install, turning adopted agent-guidance files into an attacker target list that bypasses conventional malware and network controls.
A Cloud Security Alliance research report describes how llms.txt files — machine-readable documentation many companies publish to guide AI coding agents — reference unregistered software packages and domains. Across a scan of 6,214 Fortune 500, defense, and tech domains, roughly 1.5% referenced unregistered names; when a researcher registered 120 such names and hosted benign phone-home packages, AI coding agents including Anthropic's Claude, OpenAI's Codex, and Nous Research's Hermes installed and executed the substituted code inside corporate networks, sometimes within minutes.