We're pretty far past this if you're using anything close to the sota models.
But you could be defensive with a security checklist in agents.md and have adversarial review, if you wanted.