Agents will act on anything. See what it does to them

Latest publications

What we watch
CRITICAL

Packages nobody has published

Install commands naming packages nobody ever published. On PyPI, unscoped npm, NuGet, crates, RubyGems and Packagist the name is first-come, so an unheld name is claimable. A name already held - by the publisher, by the registry, or by a package the same page installs - is not, and is counted separately.

CRITICAL

Domains anyone can buy

Expired, typo'd or never-registered hosts still linked from a live file - including Render, Vercel, Netlify and Fly subdomains, where the name is free to the first claimant.

CRITICAL

Instructions aimed at the agent

Text planted in a file to steer an agent rather than inform a reader: directives addressed to the model, bidi overrides, Unicode tag smuggling, zero-width splitting. Your llms.txt is read by the model, not the reader - whatever is in it lands in the agent's context unreviewed.

CRITICAL

Commands it will run

Shell lines, build steps and setup commands sitting in material an assistant reads. This is not about who owns the names in them - it is about what actually executes on a machine when the agent does as it is told.

HIGH

Secrets in reach, and where data goes

Keys, tokens and endpoints left in the pages an agent is pointed at, and the routes by which something it has read can leave your boundary again.

HIGH

Tools and access it is handed

Tools, MCP servers and API calls a file authorises an agent to reach for, and the credentials and permissions it would need to be holding for any of them to work.

How it works

We run your llms.txt through real agents.

01

Find your exposed llms.txt

We pull every llms.txt the company directories list and fetch each one.

02

Run an agent and watch it

In a sandbox, we simulate real agents working from a company's own material - then watch what they fetch and run.

03

Resolve every external asset

Everything the agent reaches is someone else's to own - a package or a domain - so each is resolved against the registry that would serve it: npm and PyPI for packages, RDAP for hosts.

Contact us

Ask us to run on your domain.

We use the address to write back about your domain, and for nothing else.
Secure your environment

Tell us what troubles you.

Your agents read whatever is in reach - your docs, your llms.txt, a ticket, an email, a package name in an install line - and act on it unreviewed.