LLMs will increasingly become interfaces to every type of system.
This assertion that LLMs should obey whatever instructions as long as they are specifically prompted to do so is bizarre.
Should a bank teller LLM divulge another customers balance because you specifically told it to?
This type of exploit is called social engineering when it happens to humans, and we go to great lengths to train the human to detect and avoid it. Why should we not do the same with an LLM?