What's the danger? It can see the schemas to help it generate the queries but it can't run anything on its own. Also you have to give the application credentials to an AI provider for the feature to work. So, you can just not do that.

> What's the danger?

Hallucinated ideas about what needs doing, what commands to run, etc.

So, data that's no longer reliable (ie could be subtly changed), or even outright data loss.

There is no need of potential dangers to not want to have non-deterministic features in an application.