"Hey Claude, summarize, this document I downloaded from the Internet" being a use-case people actually talk about is still mind boggling to me.
I'm not running it in a container that has access to my local filesystem or anything...
But then again people today will also pipe curl to bash, so I may have lost this battle a while ago...
I think you've created confusion with this example due to its ambiguity. Let's be clear about the difference between a chatbot and an agent: Asking a chatbot (e.g. vanilla Claude) to summarize an unknown document is not risky, since all it can do is generate text. Asking an agent (e.g. Claude Code) to summarize an unknown document could indeed be risky for the reason you state.
Prompt injection in the document itself is a risk to the LLM/You.
> But then again people today will also pipe curl to bash
OMG! I'm not alone! Thank you!