以色列一家隐身初创公司的研究人员发现,超过100个网站的 llms.txt 和 llms-full.txt 文件中引用了未被注册的代码包或域名,这些内容会被AI代理自动执行 1。研究团队在扫描6214个活跃域名后,共发现8265个 llms.txt 和 llms-full.txt 文件,其中120个文件指向了未注册的代码包或域名 1。这些文件中引用了潜在危险的自动执行内容,且至少有一个配置错误的网站将访问者导向了实时恶意软件 1。
为验证该风险,研究人员注册了部分未声明的名称并托管了探测代码,仅一小时内便收到了一家财富500强公司的回连响应 1。调查最终确认,Claude、OpenAI的Codex以及Nous Research的Hermes等编程代理参与了执行,共有数十家公司运行了这些概念验证代码,其中包括部分财富500强企业 1。在发布时,Anthropic、OpenAI和Nous Research均未回应置评请求 1。
Researchers from an Israeli stealth startup discovered that documentation files on over 100 websites referenced unregistered code packages or domains that are automatically executed by AI agents 1. The team scanned 6,214 active domains and identified 8,265 llms.txt and llms-full.txt files 1. Among these, 120 files pointed to unregistered code packages or domains 1.
To test the vulnerability, the researchers registered some of the undeclared names and hosted probe code 1. Within one hour, they received a callback response from a Fortune 500 company, confirming that programming agents including Anthropic's Claude, OpenAI's Codex, and Nous Research's Hermes participated in the execution 1. Dozens of companies, including several Fortune 500 firms, executed the proof-of-concept code 1. The investigation also revealed that at least one misconfigured website directed visitors to live malware 1.
At the time of publication, Anthropic, OpenAI, and Nous Research had not responded to requests for comment 1.
评论
还没有评论,欢迎留下第一条。