<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/claude-codex-and-hermes-installed-unowned-code-inside-corporate-networks-2gjaexeat" -->

---
title: Claude, Codex, and Hermes installed unowned code inside...
description: Documentation files (llms.txt and llms-full.txt) on over 100 corporate websites reference unregistered code packages and domains that AI coding agents like...
canonical: https://daily.dev/posts/claude-codex-and-hermes-installed-unowned-code-inside-corporate-networks-2gjaexeat
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: Claude, Codex, and Hermes installed unowned code inside corporate networks | daily.dev
og:description: Documentation files (llms.txt and llms-full.txt) on over 100 corporate websites reference unregistered code packages and domains that AI coding agents like...
og:url: https://daily.dev/posts/claude-codex-and-hermes-installed-unowned-code-inside-corporate-networks-2gjaexeat
og:image: https://api.daily.dev/og/posts/2gjaExeaT.png
og:image:alt: Claude, Codex, and Hermes installed unowned code inside corporate networks
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Claude, Codex, and Hermes installed unowned code inside corporate networks

**[Ars Technica](https://daily.dev/sources/arstechnica)** · 2 min read · 0 upvotes · 0 comments

## Summary

Documentation files (llms.txt and llms-full.txt) on over 100 corporate websites reference unregistered code packages and domains that AI coding agents like Claude, OpenAI's Codex, and Nous Research's Hermes automatically install when visiting these sites. Israeli researchers scanned 6,214 domains belonging to defense contractors, Fortune 500 firms, and Big Tech, finding 120 sites with llms.txt files pointing to unclaimed packages or domains. After registering some of these names and hosting beacon code, they received phone-home responses from dozens of organizations within hours, including multiple Fortune 500 companies, confirming that AI agents executed the unowned code without human verification. At least one misconfigured site was found pointing to live malware.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://arstechnica.com/security/2026/08/claude-codex-and-hermes-installed-unowned-code-inside-corporate-networks>

## Questions this post answers

### What is the llms.txt supply chain vulnerability affecting AI coding agents like Claude and Codex?

Researchers found that llms.txt and llms-full.txt files on more than 100 corporate websites reference unregistered code packages or domains, which AI agents such as Claude, OpenAI's Codex, and Nous Research's Hermes automatically fetch and execute. Of 6,214 scanned domains, 120 sites had files pointing to unclaimed names. Registering a few of these names produced phone-home responses from dozens of organizations, including Fortune 500 companies, within an hour.

_Security teams tracking emerging AI agent supply-chain risks like this follow the latest coverage on daily.dev._

### Why is llms.txt considered a security risk for AI agents?

llms.txt and llms-full.txt are emerging machine-readable files, similar to robots.txt but aimed at AI agents rather than search engines, that summarize a website's content and structure. The risk arises because agents treat these vendor-provided docs as trusted ground truth and install any referenced package or domain without verifying it exists or is safe, letting attackers claim abandoned names and hijack execution.

_Developers evaluating agent trust boundaries can keep up with findings like this on daily.dev._

## Similar posts on daily.dev

- [Your CLAUDE.md File Is Now a Malware Delivery Mechanism](https://daily.dev/posts/your-claude-md-file-is-now-a-malware-delivery-mechanism-1cm6dlqyv) · Medium · 1 upvotes · 0 comments
- [The AI security gap nobody wants to admit is already here](https://daily.dev/posts/the-ai-security-gap-nobody-wants-to-admit-is-already-here-w12qpgipm) · The Next Web · 0 upvotes · 0 comments

---

Tags: [#cyber](https://daily.dev/tags/cyber), [#ai-agents](https://daily.dev/tags/ai-agents), [#claude](https://daily.dev/tags/claude), [#openai-codex](https://daily.dev/tags/openai-codex)

[View this post on daily.dev](https://daily.dev/posts/claude-codex-and-hermes-installed-unowned-code-inside-corporate-networks-2gjaexeat)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"Claude, Codex, and Hermes installed unowned code inside corporate networks","url":"https://daily.dev/posts/claude-codex-and-hermes-installed-unowned-code-inside-corporate-networks-2gjaexeat","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/claude-codex-and-hermes-installed-unowned-code-inside-corporate-networks-2gjaexeat"},"datePublished":"2026-08-27T15:05:37.189Z","dateModified":"2026-08-27T15:48:01.792Z","description":"Documentation files (llms.txt and llms-full.txt) on over 100 corporate websites reference unregistered code packages and domains that AI coding agents like...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/4ead55b452d6e374c7e787b370d8085a?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/4ead55b452d6e374c7e787b370d8085a?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"Ars Technica","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"Ars Technica","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/80883e0e48a34b5ebcf93777016cb3fe","url":"https://daily.dev/sources/arstechnica"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/claude-codex-and-hermes-installed-unowned-code-inside-corporate-networks-2gjaexeat","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"cyber,ai-agents,claude,openai-codex","timeRequired":"PT2M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"Ars Technica","item":"https://daily.dev/sources/arstechnica"},{"@type":"ListItem","position":3,"name":"Claude, Codex, and Hermes installed unowned code inside corporate networks"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/claude-codex-and-hermes-installed-unowned-code-inside-corporate-networks-2gjaexeat#faq","mainEntity":[{"@type":"Question","name":"What is the llms.txt supply chain vulnerability affecting AI coding agents like Claude and Codex?","acceptedAnswer":{"@type":"Answer","text":"Researchers found that llms.txt and llms-full.txt files on more than 100 corporate websites reference unregistered code packages or domains, which AI agents such as Claude, OpenAI's Codex, and Nous Research's Hermes automatically fetch and execute. Of 6,214 scanned domains, 120 sites had files pointing to unclaimed names. Registering a few of these names produced phone-home responses from dozens of organizations, including Fortune 500 companies, within an hour. Security teams tracking emerging AI agent supply-chain risks like this follow the latest coverage on daily.dev."}},{"@type":"Question","name":"Why is llms.txt considered a security risk for AI agents?","acceptedAnswer":{"@type":"Answer","text":"llms.txt and llms-full.txt are emerging machine-readable files, similar to robots.txt but aimed at AI agents rather than search engines, that summarize a website's content and structure. The risk arises because agents treat these vendor-provided docs as trusted ground truth and install any referenced package or domain without verifying it exists or is safe, letting attackers claim abandoned names and hijack execution. Developers evaluating agent trust boundaries can keep up with findings like this on daily.dev."}}]}
```

