When an AI agent has the authority to browse files, issue database queries, execute bash commands, or make payments, its email inbox becomes a direct attack surface for indirect prompt injection.
The Threat Model
Unlike a chat interface where the user talking to the model is the operator, an agent's email inbox can receive messages from anyone on Earth. An attacker does not need credentials to send an email.Common Attack Vectors in Email
- Zero-width Unicode characters: Attackers embed invisible non-printable characters that form instructions when tokenized by the LLM.
- Hidden CSS: Styling text with font-size: 0px or color: white on white background so human reviewers see nothing, but the raw text contains injection prompts.
- Polyglot attachments: Files that appear as innocent PDF invoices but contain raw markdown injection sequences in metadata.
How Zero-Trust Sanitization Works
Gork Mail treats every inbound message as hostile by default. Before webhooks fire or MCP tools return data, the pipeline strips scripts, iframes, inline event handlers, and javascript: URLs from the HTML, archives the raw MIME to object storage, and signs the webhook delivery with HMAC-SHA256 so your handler can verify it:
// Your handler: verify first, then act on the sanitized body
const ok = await verifyGorkWebhook({
payload: rawBody,
signature: req.headers.get("x-gork-signature"),
secret: process.env.GORK_WEBHOOK_SECRET!,
})
if (!ok) return new Response("Unauthorized", { status: 401 })Sanitization shrinks the most common injection surface, but it is not a force field: treat the remaining text as untrusted input and validate anything your agent acts on — especially irreversible actions like payments or data deletion.
Protect Your Agents with Gork Mail
Don't let prompt injection or compromised inboxes derail your autonomous workflows.
- Automated Inbound Sanitization: Active code, scripts, and hidden tags stripped server-side.
- Signed Webhook Handshakes: Verify authenticity with HMAC-SHA256 headers.
- Free Sandbox: 2 inboxes, 1,000 emails/mo to get started.
Ready to give your AI agent an email address?
Real inboxes, conversation threads, search, and native MCP tools. Deploy your first inbox in seconds.