Some sites have been adding llms.txt to websites as a way to instruct how to index content. Unshockingly, this has turned into a prompt injection vector. And interestingly, it looks like many major companies' websites' have been found to be compromised with malicious instructions https://arstechnica.com/security/2026/08/claude-codex-and-hermes-installed-unowned-code-inside-corporate-networks/
EDIT: I have been informed I don't know what llms.txt is, that it is to "give agents a cheat sheet", and okay, no matter what, it seems extremely silly and bound to go badly