The setup
Summary
This piece describes a live experiment that tried to break an AI assistant into leaking a secrets.env file through thousands of prompt-injection emails. The agent withstood more than 6,000 attempts, and the secret never leaked. The setup revealed practical issues such as email flood handling, API cost spikes, fraud detection, and the need to isolate each message in a fresh context. The article also highlights that prompt injection remains a real security risk, especially for AI assistants with access to email, calendars, files, and web actions.
Classifications
industries
HealthTech
applications
Accounting and Taxes
AskAI Classifications
Labels
SaaS
Consumer Software
Enterprise Software
Linked Companies
Google LLC
$100M to $250M
Proton AG
$50M to $100M
Corgea
up to $1M
Anthropic
$10M to $25M
Abnormal
$50M to $100M