I also feel like this is an attack that manual review is not that likely to catch, given none of the malicious code appears in any of the tool calls or output.