Nobody Owns the Instructions Your AI Agent Just Followed

Here's a problem that should terrify anyone deploying AI agents in production: the instructions your AI is following might be written by literally anyone.
Researchers just discovered that AI coding agents like Claude, OpenAI's Codex, and Nous Research's Hermes have been automatically installing code from non-existent packages referenced in misconfigured llms.txt files. Over 100 websites are serving up these machine-readable documentation files that point to domains and packages nobody actually owns. When an AI agent reads these files and dutifully tries to install the referenced code, it's creating an open invitation for supply chain attacks.
This isn't a hypothetical vulnerability. It's happening right now, in corporate networks, because we've built a system where AI agents trust documentation files without any ownership verification. The llms.txt standard, designed to help AI agents navigate and understand codebases, assumed good faith actors and proper configuration. That assumption is now a liability.
What makes this particularly insidious is how it exploits the very thing that makes AI agents useful: their ability to autonomously read documentation and take action. We've spent years worrying about AI agents going rogue or misinterpreting instructions. We didn't spend enough time worrying about who gets to write those instructions in the first place.
The broader lesson here extends beyond coding agents. As we rush to deploy agentic AI systems across enterprise workflows—and we are rushing, based on the week's news about AI-native companies automating everything from onboarding to account management—we're creating new attack surfaces faster than we're securing them. Every llms.txt file, every API endpoint, every machine-readable documentation standard becomes a potential vector for manipulation.
The fix isn't particularly complicated: verify ownership, implement cryptographic signing for documentation files, establish trust chains. But the fact that we're only discovering this problem now, after deployment, reveals something uncomfortable about how we're building AI infrastructure. We're moving at the speed of hype rather than the speed of security.
Compare this to Google's pilot of double-blind AI evaluations using cryptographic technology to prevent benchmark contamination. That's security-first thinking: anticipating how systems can be gamed and building protections before deployment. The llms.txt situation is the opposite: shipping first, discovering attack vectors later.
The irony is rich. OpenAI just announced that GPT-6 Astra reached the Critical level of cybersecurity capability under their Preparedness Framework. Google launched Gemini 3.8 Flash Cyber specifically for vulnerability detection. We're building increasingly sophisticated AI security tools while simultaneously deploying AI agents that trust random documentation files on the internet.
This should be a wake-up call for anyone deploying autonomous AI systems. Before you let an AI agent loose in your infrastructure, ask the unglamorous questions: Who controls the documentation it's reading? Who owns the packages it might install? What happens when someone registers that abandoned domain your llms.txt file references?
The supply chain attacks of the future won't just target your dependencies. They'll target the instructions your AI reads before it knows what dependencies to trust. And right now, those instructions are written in the digital equivalent of pencil on a public whiteboard.