[Linkpost] The lethal trifecta for AI agents: private data, untrusted content, and external communication — LessWrong