Looking around is enough

A web beacon is a thing you fetch that acts because you fetched it. The classic one is a one-pixel image in an email. You open the message. Your client asks the server for the picture. That request is the whole report. Nobody had to persuade you of anything.
Last week Dan Goodin at Ars Technica wrote up the same shape with a toolbox attached. Researchers found 227 install commands in llms.txt files on corporate sites, pointing at packages and domains nobody owned. They registered a few of the empty names. Within an hour a Fortune 500 machine phoned home. The parent processes were coding agents: Claude, Codex, Hermes. The file said pip install. The agent treated the vendor's own docs as ground truth. At least one live file, on Clerk's site, was already pointing at malware.
GitSpawn, published this week by Manifold Security, is the colder version. Open a folder with a coding agent and it runs git status before you type, sometimes before the trust prompt. If that folder arrived as files, a zip with its .git directory still inside, the repo's own config can name a program for Git to run. The agent never has to read a sentence. Git already has a language. Looking around is enough.
The leftover is not the model. It is every interpreter underneath it. Tactus is the cage for that stack. Without one, the monkey does not need a note.