Why a working prompt injection is a small problem here
There is a design decision underneath the desktop widget that a security team will care about, so here it is. Nothing executable crosses the wire. The server sends a capability identifier and typed arguments. The actual code lives in the signed build, in a fixed table.
So a prompt injection that works, genuinely works, gets to call another entry in that same table and nothing else. It also never gets a privilege the person using the client does not already have. That is a much smaller blast radius than an assistant which can be talked into running something new.