The setup

General News

Summary

This piece describes a live experiment that tried to break an AI assistant into leaking a secrets.env file through thousands of prompt-injection emails. The agent withstood more than 6,000 attempts, and the secret never leaked. The setup revealed practical issues such as email flood handling, API cost spikes, fraud detection, and the need to isolate each message in a fresh context. The article also highlights that prompt injection remains a real security risk, especially for AI assistants with access to email, calendars, files, and web actions.

Classifications

industries
HealthTech
applications
Accounting and Taxes

AskAI Classifications

Labels
SaaS Consumer Software Enterprise Software

Linked Companies

Google LLC
$100M to $250M
Proton AG
$50M to $100M
Corgea
up to $1M
Anthropic
$10M to $25M
Abnormal
$50M to $100M