Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. Some sites have been adding llms.txt to websites as a way to instruct how to index content.

Some sites have been adding llms.txt to websites as a way to instruct how to index content.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
4 Indlæg 4 Posters 2 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • cwebber@social.coopC This user is from outside of this forum
    cwebber@social.coopC This user is from outside of this forum
    cwebber@social.coop
    wrote sidst redigeret af
    #1

    Some sites have been adding llms.txt to websites as a way to instruct how to index content. Unshockingly, this has turned into a prompt injection vector. And interestingly, it looks like many major companies' websites' have been found to be compromised with malicious instructions https://arstechnica.com/security/2026/08/claude-codex-and-hermes-installed-unowned-code-inside-corporate-networks/

    EDIT: I have been informed I don't know what llms.txt is, that it is to "give agents a cheat sheet", and okay, no matter what, it seems extremely silly and bound to go badly

    bovaz@misskey.socialB gaditb@icosahedron.websiteG purple@nya.socialP 3 Replies Last reply
    1
    0
    • cwebber@social.coopC cwebber@social.coop

      Some sites have been adding llms.txt to websites as a way to instruct how to index content. Unshockingly, this has turned into a prompt injection vector. And interestingly, it looks like many major companies' websites' have been found to be compromised with malicious instructions https://arstechnica.com/security/2026/08/claude-codex-and-hermes-installed-unowned-code-inside-corporate-networks/

      EDIT: I have been informed I don't know what llms.txt is, that it is to "give agents a cheat sheet", and okay, no matter what, it seems extremely silly and bound to go badly

      bovaz@misskey.socialB This user is from outside of this forum
      bovaz@misskey.socialB This user is from outside of this forum
      bovaz@misskey.social
      wrote sidst redigeret af
      #2
      @cwebber@social.coop "LLMs can’t draw a reliable boundary between authentic user instructions entered directly into a prompt and content they find on untrusted third-party sources." always beautiful.
      Am I right in understanding that those websites are injecting potentially malicious instructions "into" LLMs that are crawling them?
      I think I don't mind that, right now.
      1 Reply Last reply
      0
      • cwebber@social.coopC cwebber@social.coop

        Some sites have been adding llms.txt to websites as a way to instruct how to index content. Unshockingly, this has turned into a prompt injection vector. And interestingly, it looks like many major companies' websites' have been found to be compromised with malicious instructions https://arstechnica.com/security/2026/08/claude-codex-and-hermes-installed-unowned-code-inside-corporate-networks/

        EDIT: I have been informed I don't know what llms.txt is, that it is to "give agents a cheat sheet", and okay, no matter what, it seems extremely silly and bound to go badly

        gaditb@icosahedron.websiteG This user is from outside of this forum
        gaditb@icosahedron.websiteG This user is from outside of this forum
        gaditb@icosahedron.website
        wrote sidst redigeret af
        #3

        @cwebber ln -s robots.txt llms.txt

        Like oh sorry you CAN look for and read standardized .txt files in the root directory now? Wow! It took you so long to implement that feature, I'm so proud you finally figured out how to do that, that must have been a lot of work.

        1 Reply Last reply
        0
        • cwebber@social.coopC cwebber@social.coop

          Some sites have been adding llms.txt to websites as a way to instruct how to index content. Unshockingly, this has turned into a prompt injection vector. And interestingly, it looks like many major companies' websites' have been found to be compromised with malicious instructions https://arstechnica.com/security/2026/08/claude-codex-and-hermes-installed-unowned-code-inside-corporate-networks/

          EDIT: I have been informed I don't know what llms.txt is, that it is to "give agents a cheat sheet", and okay, no matter what, it seems extremely silly and bound to go badly

          purple@nya.socialP This user is from outside of this forum
          purple@nya.socialP This user is from outside of this forum
          purple@nya.social
          wrote sidst redigeret af
          #4
          @cwebber@social.coop damn, the jig is up!

          i've also had hits to /AGENTS.md so definitely don't put instructions in it for the agent to install your personal ssh key on their infra or something totally benign like that 🙂
          1 Reply Last reply
          0
          • jwcph@helvede.netJ jwcph@helvede.net shared this topic
          Svar
          • Svar som emne
          Login for at svare
          • Ældste til nyeste
          • Nyeste til ældste
          • Most Votes


          • Log ind

          • Har du ikke en konto? Tilmeld

          • Login or register to search.
          Powered by NodeBB Contributors
          Graciously hosted by data.coop
          • First post
            Last post
          0
          • Hjem
          • Seneste
          • Etiketter
          • Populære
          • Verden
          • Bruger
          • Grupper