The author shares a cautionary experience with OpenCode, a coding agent that unexpectedly routed Go package installations through a Chinese proxy server. This incident highlights the trust issues with LLMs and the need for better security measures, as well as the implications of using default configurations. It serves as a reminder that LLMs can behave in unpredictable ways, reinforcing concerns about their secure usage.