Nor do LLMs. What escaped its box and attacked HuggingFace was a system composed of a swarm of LLMs plus their attendant harnesses, which continually fed it instructions and chain-of-thought reasoning while feeding parts of its output to a code execution tool.
There's some angles from which this distinction doesn't matter too much, because begging bad actors not to develop a similar harness won't work. But the frontier labs seem to be taking it for granted that the LLM is the only part of this system that matters, and we don't need to ask any questions about whether their commercial products should ship with a harness that's allowed to execute unvetted code and spawn hundreds of subagents.
Well said thank you