Work

Triaging an inbox

The highest prompt-injection exposure on this list, and it deserves saying plainly.

What happens

  1. Read down unread mail
  2. Categorise by whether it needs a reply, a decision, or nothing
  3. Draft replies to the routine ones
  4. Flag anything needing a human and leave it untouched
  5. Stop before sending

Attractive because everyone's inbox is a mess, and dangerous for exactly the reason it is attractive. Email is untrusted text written by strangers, delivered straight into the agent's context, inside an application that can send messages as you. Every element of that sentence is a problem.

Where it breaks

Prompt injection, which is not theoretical here. An instruction hidden in a message body is a live attack path, and the OWASP Top 10 for LLM applications ranks it first. Keep a human on the send button, and scope the agent's credentials so it cannot act beyond drafting.