Fair point but it's not social either. It's a new class of exploit that's based on tricking the AI.

It's not based on plugging an LLM into an area where it doesn't belong in the first place?