Your model/harness will indiscriminately do web searches to get answers. I believe that’s where the real risk is.
It could be as simple as a malicious prospectus for AcmeCo, and then try to get AcmeCo on the radar so that the LLM-tools find your document and incorporate it. The malicious bits don't even need to be AcmeCo-related, they could be to pump (or dump) practically anything.