However, if you don't put your administrative credentials inside of the VM and treat it as an unsafe environment you can safely give it minimal permissions to access specific things that it needs and using that access it can perform complex tasks.
https://simonwillison.net/2024/Mar/5/prompt-injection-jailbr...