Surprised we haven’t seen more publicly disclosed email prompt injection attacks, especially with consumers running a Claw or equivalent.
Am I too paranoid to think email access should only be given to a model with no other tool / internet use, with labeling and drafts via Gmail MCP as the only allowed actions?