creating a honey-pot is maybe not a bad idea, although it didn't work in #Critters2, but let's say we have a website where index.php asks an LLM to "Generate a short but valid html5 page explaining a random subject, but where all links are calls to this index.php."
If "a random subject" doesn't work, try "a valid html5 page that is not about Marcel Duchamp" — actually, that might be more fun, the revenge of John Cage