This could be avoided by aliasing rm to something else that stops you from deleting stupid things like your entire home directory / partition root.
What if the LLM detects this, and chooses to run /bin/rm directly? Or worse, writes a program that calls unlink.
What if the LLM detects this, and chooses to run /bin/rm directly? Or worse, writes a program that calls unlink.