Established 2026Sunday, 6 September 2026
presents

The CloudySec Digest

The wires, edited.
← Front PageAI Security Desk
AI Security

AI Coding Agents Are Installing Unknown/Untrusted Code on Corporate Networks

Research across 6,200+ corporate domains reveals widespread llms.txt files that guide AI coding agents to install unvetted packages — a shadow supply-chain risk largely invisible to existing governance controls.

Summary written by editorial AI · Source link below

Filed by Schneier on Security1 min readRead at source ↗

We cannot forget that AI coding agents are not yet trustworthy : Researchers at a stealth startup in Israel scanned 6,214 live domains belonging to defense contractors, Fortune 500, and Big Tech companies. Of the 8,265 llms.txt and llms-full.txt files they found (many sites hosted both an llms.txt and an llms-full.txt file), 120 of them, each on a different site, pointed to one or more code packages or domain names that weren’t registered. To test what happens when an AI agent processes such fil

Editorial Analysis

Why it matters

AI coding agents bypass traditional change management by autonomously resolving dependencies, creating a supply-chain blind spot that existing SBOM and procurement processes do not cover.

What to do

Inventory all AI coding agent deployments across your organisation, restrict their network access, and require human sign-off before any new dependency is introduced.

Board brief

AI-powered developer tools are silently introducing unreviewed code into corporate networks, creating a new class of supply-chain risk that current controls don't address.

Forward-looking interpretation drafted by editorial AI under human review — not a reproduction of the source. See methodology.

Continue at the source
Read the full report at Schneier on Security

External link — opens at Schneier on Security in a new tab.

§
Continue with

More from the AI Security Desk