If you research the ways data can be leaked out of an LLM interaction you can see some more subtle cases.
What if I ask it to replace every vowel in the secret code with an emoji from a library? Or translate it into binary? Etc.
Whether or not this implementation is narrow (by design), there's a good reason to invest in this kind of safety and security space.