Earlier quoted context omitted.
They could prevent the rendering engine and llm from doing any http calls, prompting the user to allow the engine and llm for each call it needs to make, showing the call details.
That’d provide some protection, but the LLM could be prompted to socially engineer users. For example, it could be promoted to only make malicious HTTP requests via an image when the user genuinely requests an external image be created. This would achieve consent from users who thought they were asking for a safe external source. Similar for fonts, external searches [1], social items etc [1] e.g putting a reverse pro…
> showing the call details.
If you really want to render an image, a huge base64 blob would be a bit suspisouse for a url that should simply point to a png or similar.