The inference engine itself does not execute anything. The agent loop is what may execute a command.
So I think this article is a kind of strange.
Or maybe the author means that a prompt could potentially mess up the inference. But I find it hard to see how that could take control over the host.