// why
Why not connect your whole inbox?
In short
- The usual way to give an agent email is an OAuth connection to your whole mailbox, often with permission to send as you.
- The agent then reads every message a stranger can deliver, and a message can carry instructions written for the agent rather than for you.
- A filtered view shrinks what such a message can reach: only the mail you chose to forward, with no way to send or delete.
1.What one email has done
Security researchers have repeatedly shown assistants with mailbox access following instructions hidden in a message. Each problem below was fixed after disclosure, and none is known to have been used against real users. They show the shape of the risk, not a count of breaches.
- 1.EchoLeak, June 2025. Aim Security showed that one crafted email could make Microsoft 365 Copilot send data from its context to an attacker when the recipient later asked Copilot a related question, without the recipient clicking anything. Microsoft fixed it on its servers before disclosure (CVE-2025-32711). Microsoft advisory · Aim Security write-up
- 2.Invitation Is All You Need, August 2025. Researchers from Tel Aviv University, the Technion and SafeBreach showed that hidden instructions in a calendar invite or an email subject could make Google’s Gemini assistant delete calendar events, leak email subject lines or operate smart-home devices when the user asked about their schedule or mail. Google had deployed mitigations before the research was presented. SafeBreach write-up · Paper
- 3.Claude in Chrome, August 2025. Anthropic’s own testing found that, before new defenses, a malicious email asking for “mailbox hygiene” led Claude in Chrome to delete a user’s emails without confirmation. Anthropic published the result and says its mitigations block that attack. Anthropic announcement
- 4.ShadowLeak, September 2025. Radware showed that a single crafted email could make ChatGPT’s Deep Research agent, when asked to research the user’s Gmail, send inbox data to an attacker’s server directly from OpenAI’s cloud. OpenAI fixed it before disclosure, and Radware reported no exploitation. Radware write-up
2.What the vendors advise
Google’s developer documentation for its Gmail MCP server warns: Avoid asking your MCP client to process emails or other resources from unverified sources. These inputs may contain hidden instructions that can hijack your session, allowing an attacker to modify, steal, or delete your data.
Source.
That advice is hard to follow when the agent can read the whole mailbox, because most mail comes from senders nobody has verified.
3.What a filtered view changes
You forward only the mail an agent needs to a private em[ai]l. alias. The rest of your inbox never reaches the service, and the service requests no mailbox permission, so it holds no token that could expose the rest of your inbox.
An agent connection reaches one address and can only read and draft. There is no tool that sends or deletes mail, so an injected instruction cannot use em[ai]l. to send as you. Stored mail is encrypted and expires on the schedule you set.
4.What it does not change
A forwarded message can still carry instructions aimed at your agent, and anyone who learns your alias can send to it. Senders are not authenticated, so everything the agent reads is marked untrusted. Forward only what the agent needs, and review drafts before you send them.
Your agent’s other tools are outside this boundary. If it can also browse, run code or reach other accounts, an injected instruction can try to use them. The security model lists what the service does and does not protect against.
5.Questions to ask of any email connector
Ask these before connecting any mail service to an agent, including this one. Each answer below is for em[ai]l., and the security model explains how each is enforced and where it stops.
- 1.What can the service read? Only mail delivered to your alias.
- 2.Does it hold a token to your mailbox? No. It never requests mailbox permission.
- 3.Can the agent send, delete or change settings? No. Its tools read and draft only, for one address.
- 4.How long does it keep your mail? The retention period you set for each address, then it expires.
- 5.Who else can put mail in front of the agent? Anyone who learns the alias, so all mail is marked untrusted.
Ready to try it? The setup guide takes you from sign-in to your agent’s first message.