There's a clear solution to the danger posed to free software projects by accepting hostile submissions but it probably is not one that maintainers want to hear: they can use an agent to check submissions for nefarious patterns.
Sometimes you fight fire with fire.
And sometimes you fight this by disabling PRs in Github, and do not put more water into LLM providers' wheel.
So next the attacker puts prompt injection in their PRs & take control of the agent on your end. Perfect, 10 out of 10.