Ctrl+F "poisontap" in https://mail.gnome.org/archives/networkmanager-list/2016-November/thread.html
Instead of prompting the user every time something is plugged in, I presume the smart approach would be to block DHCP at the udev level while the gnome-shell screen is locked.
Once a solution is found in PureOS, it should be advertised as a feature, and upstreamed (if possible/accepted) to GNOME.