It’s pretty much impossible to stop the AI from producing irrelevant recitations about files, or to stop free reign over them from an unprivileged user, even those files that are meant to be internal, when OpenAI has damaged Assistants and Responses in this cleverly droll manner:
And you get these abominations.