If you’re dumb enough to have your nuclear detonator or whatever accessible via an HTTP request then it doesn’t matter how good or bad the chatbot is.
You don’t need a chatbot to have your actual life ruined by something with limited intelligence [0]. This will only be a problem if stupid humans let “it” out of the box.
In that scenario, I'd be more worried about it getting onto a thumb drive ala Stuxnet than HTTP.
...or perhaps there's some interesting new vector that we haven't thought of yet that would allow it to leap that air-gap.
I don't think any of this requires a crack team of criminals breaking into an orbital spa and whispering in the ear of a mechanical head. It'll be something boring.
More like first computer worm jumping from VAX to VAX, bringing each machine to a halt in the process.