It’s actually worse than that though. An LLM is like letting attacker controlled content on the page inject JavaScript back into the page.
Reply on news.ycombinator.com