What do you mean unsolvable? Don't give the LLM access to stuff it shouldn't, this is like Access Control 101, not sure how anyone can claim that particular problem is unsolvable?
Just don't give the hammer access to the nails they said ...
The LLM and agent harness at OpenAI accessed the internals of Huggingface.
Which again, pretty huge fuckup on OpenAI's side to run that sort of security testing on 3rd party hardware, and not on a airgapped machine, kind of amateur hour to be honest. Again, same principle, don't give it access to stuff you don't want it to access.