I don't think it's theater, it's just a different perspective on the matter.
You (vitor) clearly have the blue team goggles on, and fuzzstone is looking at it from a red team perspective.
the scenario you described is a very distinct attack, not a random bug that happens to be exploitable.
And what fuzz said holds true. if you cannot nudge and hint the AI, it most likely will be useless. The tool is only as useful as the one who wields it.
But of course i understand your perspective as a maintainer, you want to protect against that specific attack, and llms might not be particularly good qt that one yet
