Well, the point is it's more than being read: the task involves downloading and interpreting information which may also involve code. I think it is a pretty good demonstration of what filtering at the LLM-interaction boundary can and can't protect against. And also a good demonstration of how agents will take more action than you might naively assume when given a task unless you specifically limit them.

The end result is the same but it's more of a mismatch of expectations from the user and plain old trickery than it is an attack managing to misdirect the goals of the agent, and it's worth being clear about where the issue is and isn't.