0
Applied AI·August 30, 2026·1 min read

Top AI tools including Claude, Codex, and Hermes installed suspicious code inside corporate networks

Share

LLM ‘squatting’ via llms.txt and llms-full.txt is a new supply-chain attack surface—prompting AI tools to pull and run untrusted code from what looks like documentation. Treat AI dev tooling like any other executable: lock down what it can fetch, run, and connect to, and add llms*.txt checks to your security reviews this week.