@jonny If I recall correctly, some infosec folks have already successfully demonstrated such an attack on LLMs (this is distinct from the "register packages with commonly-LLM-fabricated names" attack)
@jonny "Surely they would've thought of this? Right? RIGHT?"
(This is the theme song that plays in my mind half the time I'm doing code auditing for work)
@joepie91 see that's the kind of "it must necessarily be the case based on their nature but it is so obvious and funny that it can't be real" vuln i love to see