If they're going agentic and using the stack that they're using (qt/shell scripts?) they'll never patch it in full, if ever. The thing is almost certainly full of injection/forgery attacks, on top of being bloated to oblivion.
No reason Qt or quickshell is any different from any other software.
Bash is... harder, not impossible. I wouldn't rely on it.