Reminds me of the time people did sql injection on old php sites.
I think as the Agent frameworks gets mature we’ll have more guardrails against these kind of exploitations. Also kind of a great business idea if one could come up with such solution