Don't hand your AI agent your personal email. Give it a mailbox of its own.

By neonharbour · · 6 replies

Recurring mistake I keep seeing (and made myself): you build an agent that needs to send/read email, so you paste in your personal email's OAuth token and let it loose. Now a prompt-injected message can make your agent send mail as you, and there's no policy layer between the LLM and your inbox.

The cleaner pattern is to give the agent its own managed inbox a real address, not a borrowed one plus rules that run before the agent ever reads a message.

Full disclosure, I work on the Nylas CLI, so I'm biased. But the "give your agent a human's inbox" anti-pattern predates us and it's the part I'd want people to get right regardless of tool.

Here's the approach. One-time setup signs you up, connects an email account, and spins up a free domain for agent accounts:

* # signup + connect email + free agent-accounts domain nylas init*

Then provision a dedicated address (no OAuth handshake, no human mailbox) and attach policies:

*# add a guardrail that runs before the agent sees mail # e.g. block a sender domain outright nylas agent rule create \ --condition from.domain,is,example.com \ --action block*

The address can send transactional mail and receive replies, so the agent has a real two-way channel instead of a fire-and-forget SMTP hack. Policies can block / archive / route messages before they hit the model the part people skip and then get burned by prompt injection.

Wire it into an agent through MCP and the model gets email as a tool without you hand-rolling Gmail/Graph API code per provider.

How's everyone else scoping inbox access for agents? Separate account + policies, or something else?

Editing your thread.
Reply
Add images Up to 2 images, 3MB each.
0/2
You must be signed in to reply.
Replies

copperwave5

genuinely curious how you handle the case where the agent needs to reply to a thread that was originally sent to a human's inbox though, like if a client emails your personal address and you want the agent to follow up, do you just forward to the agent inbox and lose the thread context or is there a cleaner way to hand that off?

NovaShift

the prompt injection angle is the one that gets people because it sounds theoretical until it actually happens, had a client nearly send a very embarrassing email to their entire list because of exactly this, separate inbox with policies is non-negotiable now for anything I build

Neondrift8

I made the same mistake when I built my first agent. I let it access my real inbox and instantly regretted it when it started drafting replies to emails I definitely didn’t want it to mess with.Looking back, the separate inbox idea seems so obvious, but no one really brings it up until something goes sideways. 😅

Related discussions

Popular in this category