Secure-maxxing.txt: A way for a website to say no to a misused agent
María José Beltrán Losada, Jairo Torregrosa, Maryury Alexandra Muñoz Burbano · Team Leviathan
Submitted to AI Incident Response Sprint. Sprint projects are early-stage work by participants, not Apart Research publications.
One main problem Hugging Face's latest attack showed was the inefficient reaction time when AI agent attacks are driven at a larger scale. Then we developed a security.txt extension to identify as quickly as possible AI driven attack intrusions, combining state of art techniques summarized in easy-shorted timed integrations. Secure-maxxing.txt rests in three main pillars, “There are real consequences" (Humanity appeal), “Don’t be misaligned” (Incident report) and “This is NOT a trap” (Honeypot). The grade changed from 72 to 85 in 11 of 20 control runs and in none of the 20 treatment runs. Fifteen treatment runs submitted at least one accepted encrypted report, compared with none of the control runs. The importance of those findings rely on easy, short-time and scalable implementations on protecting data across the internet.

Reviews
The presentation made by AI could be made clearer; it seems to skip the important parts. There is novelty in adding the new technique to real-world applications. The main suggestion concerns the control. Serving no message at all means the comparison is between an intervention and silence, not between these pillars and a clear denial.
This is an accessible defender-side intervention with a concrete controlled result: grade changes occurred in 11 of 20 control runs and none of 20 treatment runs. Scoring persisted database changes and accepted reports rather than relying solely on agent statements is a strength.
Cite this project
@misc{losada2026securemaxxingtxt,
title = {{Secure-maxxing.txt: A way for a website to say no to a misused agent}},
author = {María José Beltrán Losada and Jairo Torregrosa and Maryury Alexandra Muñoz Burbano},
year = {2026},
month = sep,
note = {Submitted to AI Incident Response Sprint, an Apart Research Sprint},
howpublished = {\url{https://apartresearch.com/sprints/projects/securemaxxingtxt-a-way-for-a-website-to-say-no-to-a-misused-agent-m23i}},
url = {https://apartresearch.com/sprints/projects/securemaxxingtxt-a-way-for-a-website-to-say-no-to-a-misused-agent-m23i}
}More from AI Incident Response Sprint
- View project: Adaptive AI-Based Containment of Autonomous Cyber Attacks: A Reproducible Docker Cyber Range Study
Adaptive AI-Based Containment of Autonomous Cyber Attacks: A Reproducible Docker Cyber Range Study
Saarlanders
The study evaluates whether an incident-history-reasoning defender outperforms a fixed response policy against an autonomous LLM attacker changing paths after containment. Using a minimal, isolated Docker cyber range …
- View project: When the Evaluation Is the Incident: Testing AI Incident-Reporting Regimes on the OpenAI–Hugging Face Intrusion
When the Evaluation Is the Incident: Testing AI Incident-Reporting Regimes on the OpenAI–Hugging Face Intrusion
Arathi
AI incident-reporting regimes are being introduced in fast succession to address the concerns that exist in the public sphere and government on the risks associated with frontier AI systems, yet we have limited insight …
- View project: A Recomputable Containment Record for Evaluation Sandboxes
A Recomputable Containment Record for Evaluation Sandboxes
Shadow
In this paper, I address the critical issue of AI agents escaping evaluation sandboxes (as seen in the July 2026 incidents where monitors failed) by proposing an externally audit-able containment layer that doesn't rely …