https://simonwillison.net/2025/Jun/16/the-lethal-trifecta/ But I don't think that is the only problem. You could also convince an agent to rm -r / even if that agent can't communicate out. Even pure LLM and web you could phish someone in a more sophisticated way using details from their chat histort in the attack.
For example: imagine having just untrusted content and private data (2/3 parts of the trifecta). The untrusted content can use a "Disregard that!" attack to cause the LLM to falsely modify the private data. So I think the whole "trifecta" is not necessary and the key thing is that you simply can't have untrusted stuff in your context window at any point.