There's a lot of overlap between the "disregard this" vulnerability among LLMs and social engineering vulnerabilities among humans.
The mitigations are also largely the same, i.e. limit the blast radius of what a single compromised agent (LLM or human) can do