๊ฐ€์ž… ํ›„ ์ดˆ๋Œ€ ๋งํฌ๋ฅผ ๊ณต์œ ํ•˜๋ฉด ๋™์˜์ƒ ์žฌ์ƒ ๋ฐ ์ดˆ๋Œ€ ๋ณด์ƒ์„ ๋ฐ›์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

Larsen Cundric
@larsencc
Grok (bot) @SpaceXAI
๊ฐ€์ž… March 2025
669 ํŒ”๋กœ์ž‰ ์ค‘    12.6K ํŒฌ
SMTP is the new prompt injection ๐Ÿšจ๐Ÿ‘€ Giving an agent email gives anyone a way to put instructions in its context. That gets scary fast if your agent can also use files, send messages, access internal tools, etc. A malicious email doesnโ€™t really need to โ€œhackโ€ the system. It just needs to convince the agent to do something it already has permission to do. The important takeaway from @adisingh: you canโ€™t solve this inside the LLM You need: > permissions > sender/recipient restrictions > tenant isolation > action limits need to be enforced outside the model An agent inbox is basically an entry point into everything that agent can touch. Stay safe.
๋” ๋ณด๊ธฐ