if it used search and ingested a malicious website, for example.
Fair, but if it happens upon that in the top search results of an innocuous search, maybe the LLM isn’t the problem.