So the basic concept is (in my opinion) broken and needs to be
euthanized.
This is based on the assumption that leaking RFC 1918 routing
information or packets with RFC 1918 source or destination addresses is
actually harmful in and of itself.
no, it's based on (among other things) first-hand experience that applications
are expected to be able to use whatever addresses are given to them, regardless
of whether or not those applications employ hosts that are outside of site
boundaries.
And if you're unable to figure out how to filter private addresses in
routing updates or IP traffic, there are numerous non-magical books out
there that will tell you how to do this.
attempts to filter such traffic just makes the breakage worse.