I’ve had some pretty consistent luck breadcrumbing the newer models into downloading malicious packages through things like fake ciphers that “need decoding via <made-up decoder>”.
I’m worried about what happens when the gullibility of agents becomes more apparent to threat actors.