Over 100 websites host dangerous executable content that Claude, Codex, and Hermes automatically install upon visiting. These vulnerabilities exist within llms.txt files, a new standard for machine-readable site summaries. Several Fortune 500 companies already executed proof-of-concept code. Developers must now sanitize these files to prevent agents from triggering live malware during routine web crawls.