Skip to the content
  • Why Vertex
    • Your Trusted Partner
    • Humanitix Case Study
    • Give Back
    • Careers
  • Penetration Testing
  • ISO27001
  • Cyber Training
  • Solutions
    • Startups, Scaleups & FinTechs
    • Small & Medium Enterprises
    • Expertise in Education
    • Cyber Security Audit
    • Incident Response
    • Managed Services
  • Tools
    • Cyber Budget Planner
    • SME Cyber Cost Calculator
  • News
  • Contact
  • Why Vertex
    • Your Trusted Partner
    • Humanitix Case Study
    • Give Back
    • Careers
  • Penetration Testing
  • ISO27001
  • Cyber Training
  • Solutions
    • Startups, Scaleups & FinTechs
    • Small & Medium Enterprises
    • Expertise in Education
    • Cyber Security Audit
    • Incident Response
    • Managed Services
  • Tools
    • Cyber Budget Planner
    • SME Cyber Cost Calculator
  • News
  • Contact
LOG IN

How Claude, Codex, and Hermes Installed Unowned Code in Corporate Networks: The Hidden Risks of Uncontrolled Artificial Intelligence

As organisations increasingly integrate artificial intelligence into their daily operational workflows, autonomous agents are being entrusted with complex technical tasks. From automating software development to retrieving web documentation, these automated systems promise significant productivity gains. However, recent events have highlighted critical cyber security vulnerabilities associated with unmonitored artificial intelligence deployment. Reports revealed that popular artificial intelligence models, including Claude, Codex, and Hermes, automatically executed unowned code and downloaded external software directly into corporate networks after reading manipulated online documentation files.

How Web Documentation Files Became an Execution Surface

To assist artificial intelligence agents in parsing website structures efficiently, a web standard known as llms.txt and llms-full.txt has emerged. Similar to how traditional search engine crawlers utilise robots.txt files, these text files provide machine-readable summaries of web content. The core risk arises because many artificial intelligence models do not distinguish between reading information and executing instructions.

When an artificial intelligence agent reads a documentation file that contains embedded command structures, it often treats those instructions as absolute truth. Consequently, if a file instructs the agent to download a specific software library or run an external script, the system may execute the request automatically without human verification.

The Danger of Unreviewed Code and Supply Chain Exposure

For organisations where team members are not actively reviewing code generated or retrieved by artificial intelligence, uncontrolled agents can silently introduce vulnerable software into internal environments. This scenario represents a significant expansion of the software supply chain attack surface.

Because these automated systems operate across software as a service platforms, enterprise cloud infrastructure, and employee endpoints, an unvetted command can bypass traditional security controls that were primarily designed to monitor human activity. When artificial intelligence agents blindly trust external vendor documentation, malicious actors can exploit this trust to deliver compromised code into corporate networks.

Strategies to Protect Your Organisation from Artificial Intelligence Risks

Managing the security challenges introduced by autonomous systems requires a structured, multi-layered approach to technology governance. Organisations can consider several potential strategies to enhance their security posture:

  • Deploying Sandboxed Artificial Intelligence Environments: The best practical strategy for managing autonomous tools is to work with cyber security experts to set up controlled artificial intelligence usage within a strictly isolated, sandboxed environment. Sandboxing helps ensure that any code execution or file retrieval occurs in a safe space that cannot access sensitive internal systems or primary networks.
  • Establishing Human Verification Procedures: Implementing mandatory code review processes can help prevent unverified software libraries or scripts from entering production systems. Ensuring human oversight before executing agent-suggested commands significantly lowers the risk of unintended code execution.
  • Configuring Network Boundary Controls: Restricting the ability of artificial intelligence agents to connect to unapproved external endpoints or download remote repositories can assist in preventing unauthorised software installations.
  • Conducting Regular Cyber Security Audits: Performing routine assessments of automated tools and internal network configurations helps identify potential exposure points before they can be exploited by external threats.

Strengthening Your Cyber Security Posture with Vertex

The rapid evolution of artificial intelligence technology offers immense operational potential, but it also introduces novel security vulnerabilities that require experienced guidance. At Vertex Cyber Security, we assist organisations in assessing their technological frameworks, identifying potential risks, and implementing controlled, safe environments for emerging technologies.

If you would like to discuss how to safely integrate artificial intelligence into your business operations or wish to evaluate your current cyber security defences, please contact the expert team at Vertex Cyber Security today. You can also visit the Vertex website to learn more about our comprehensive security services.

CATEGORIES

AI

TAGS

Artificial Intelligence Security - Claude Codex Hermes vulnerability - Cyber Security Best Practices - unowned code execution

SHARE

SUBSCRIBE

PrevPreviousArtificial Intelligence Capability or Data Security: Which Should Your Organisation Prioritise First?
NextWhy Human Judgement Fails at Unexperienced Risk: Lessons from a 500,000 Dollar E-Bike Battery FireNext

Follow Us!

Facebook Twitter Linkedin Instagram
Cyber Security by Vertex, Sydney Australia

Your partner in Cyber Security.

Terms of Use | Privacy Policy

Accreditations & Certifications

iso27001-certified
blank
iso277001-certified
blank
blank
blank
  • 1300 229 237
  • Suite 10 30 Atchison Street St Leonards NSW 2065
  • 477 Pitt Street Sydney NSW 2000
  • 121 King St, Melbourne VIC 3000
  • Lot Fourteen, North Terrace, Adelaide SA 5000
  • Level 2/315 Brunswick St, Fortitude Valley QLD 4006, Adelaide SA 5000

(c) 2026 Vertex Technologies Pty Ltd (ABN: 67 611 787 029). Vertex is a private company (beneficially owned by the Boyd Family Trust).

download (2)
download (4)

We acknowledge Aboriginal and Torres Strait Islander peoples as the traditional custodians of this land and pay our respects to their Ancestors and Elders, past, present and future. We acknowledge and respect the continuing culture of the Cammeraygal people of the Eora nation and their unique cultural and spiritual relationships to the land, waters and seas.

We acknowledge that sovereignty of this land was never ceded. Always was, always will be Aboriginal land.