this is interesting. sparked some thoughts about agents accessing email. smtp in particular.
- smtp is the more risky vector. more parsing, more content types, etc. means more surface to hide attacks.
- smtp auth is usually username/password vs APIs where you have tokens/scoping/oauth.
- smtp defaults to not checking dmarc, dkim, spf for identity verification.
so... if you dont setup this stuff, the agent doesnt honor it, and the receiving esps dont enforce it some really, really bad things can happen no matter how good your prompt is. phishing of course instantly comes to mind.