Some sites have been adding llms.txt to websites as a way to instruct how to index content.
-
Some sites have been adding llms.txt to websites as a way to instruct how to index content. Unshockingly, this has turned into a prompt injection vector. And interestingly, it looks like many major companies' websites' have been found to be compromised with malicious instructions https://arstechnica.com/security/2026/08/claude-codex-and-hermes-installed-unowned-code-inside-corporate-networks/
EDIT: I have been informed I don't know what llms.txt is, that it is to "give agents a cheat sheet", and okay, no matter what, it seems extremely silly and bound to go badly
-
Some sites have been adding llms.txt to websites as a way to instruct how to index content. Unshockingly, this has turned into a prompt injection vector. And interestingly, it looks like many major companies' websites' have been found to be compromised with malicious instructions https://arstechnica.com/security/2026/08/claude-codex-and-hermes-installed-unowned-code-inside-corporate-networks/
EDIT: I have been informed I don't know what llms.txt is, that it is to "give agents a cheat sheet", and okay, no matter what, it seems extremely silly and bound to go badly
@cwebber@social.coop "LLMs can’t draw a reliable boundary between authentic user instructions entered directly into a prompt and content they find on untrusted third-party sources." always beautiful.
Am I right in understanding that those websites are injecting potentially malicious instructions "into" LLMs that are crawling them?
I think I don't mind that, right now. -
Some sites have been adding llms.txt to websites as a way to instruct how to index content. Unshockingly, this has turned into a prompt injection vector. And interestingly, it looks like many major companies' websites' have been found to be compromised with malicious instructions https://arstechnica.com/security/2026/08/claude-codex-and-hermes-installed-unowned-code-inside-corporate-networks/
EDIT: I have been informed I don't know what llms.txt is, that it is to "give agents a cheat sheet", and okay, no matter what, it seems extremely silly and bound to go badly
@cwebber ln -s robots.txt llms.txt
Like oh sorry you CAN look for and read standardized .txt files in the root directory now? Wow! It took you so long to implement that feature, I'm so proud you finally figured out how to do that, that must have been a lot of work.
-
Some sites have been adding llms.txt to websites as a way to instruct how to index content. Unshockingly, this has turned into a prompt injection vector. And interestingly, it looks like many major companies' websites' have been found to be compromised with malicious instructions https://arstechnica.com/security/2026/08/claude-codex-and-hermes-installed-unowned-code-inside-corporate-networks/
EDIT: I have been informed I don't know what llms.txt is, that it is to "give agents a cheat sheet", and okay, no matter what, it seems extremely silly and bound to go badly
@cwebber@social.coop damn, the jig is up!
i've also had hits to/AGENTS.mdso definitely don't put instructions in it for the agent to install your personal ssh key on their infra or something totally benign like that
-
J jwcph@helvede.net shared this topic