2) While injection has potential, this is fairly well mitigated. Look at comet and others.
These are all whataboutisms coming from a place of fear.
[1] https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/
From the article: It's a side page agent that has only access to the page, and outputs content in text only, and awaits user confirmation on actions. It's all on the page. It's I guess it's a mono-fecta?
PS: It is Gemini based, that's an LLM.
[1] https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/