Well, the discussion leaves the focus I intended it to have.
It is surely worth thinking about what a minimum templates needs to have.
Nevertheless I think Qubes is about "I know I can get exploited, so just protect the other parts of the system". Afaik a normal Qubes template has only the root user, so after an exploit the attacker is root in that VM right?

My thoughts are more about continuing the attack to other QubesVMs or even other systems by means of installed Software like a VNC client.

