
AI & email
Defending AI email assistants against hidden instructions
Layered defenses against prompt injection in email: capability limits, human approval, untrusted-content handling, hidden HTML, tool chains and logging.
5 min read

Layered defenses against prompt injection in email: capability limits, human approval, untrusted-content handling, hidden HTML, tool chains and logging.
5 min read

Send yourself harmless test emails with embedded instructions to see if your AI assistant obeys mail content. Test cases, expected behavior and a scoring sheet.
5 min read

Email is untrusted text written by anyone. Here is how prompt injection works against AI email assistants, how attackers hide instructions, and what they want.
5 min read