Lethal trifecta for AI agents: private data, untrusted content, external commssimonwillison.net3 pointstaubeka year ago