If a certain user is susceptible to having the LLM convince them to run an unsafe command, I fear we can't fix that by trying to trick the LLM. :D
Either the user needs to be educated or we need to restrict what the user themselves can do.
Either the user needs to be educated or we need to restrict what the user themselves can do.