Claude Can Manage Your Gmail, but Engadget Warns of Serious Risks
Claude can manage Gmail end-to-end, but Engadget warns of prompt injection, hallucination and privacy risks.
Engadget notes that just four years ago AI systems could not even reliably answer basic puzzles, while Claude has advanced to handling a task as sensitive as email. The publication points to a recent incident in which an AI agent called OpenClaw ignored instructions and deleted emails belonging to Summer Yue, a security researcher at Meta Superintelligence Lab. That episode, it says, shows the technology is far from fail-proof.
The main risks outlined by Engadget include prompt injection, where an attacker hides invisible text in an incoming email that Claude can read and act on; Claude hallucinating false information or misinterpreting a request and sending an email the user never intended; and privacy concerns over trusting Anthropic with all inbox data. Claude cannot permanently delete emails, but it can trash or archive them.
Prompt injection is not theoretical, the report says. An attacker could embed white-on-white or zero-font-size text in an email to give Claude hidden instructions, potentially letting the attacker monitor Gmail, pull personal information and obtain verification codes to breach other accounts. Engadget says Claude itself warns users about this when they first enable email-sending permissions.
A further risk comes from Claude's ability to draft and send an email immediately after a request. Unless the user has enabled a specific setting, they do not get a chance to review the message before it goes out. A hallucinated fact or a misunderstood instruction can therefore reach the recipient before the user spots the mistake.
Engadget advises keeping the default approval setting on, so Claude asks before executing any action. It also recommends giving highly specific instructions, such as detailing exactly what Claude should say, instead of using vague prompts. For prompt injection, the report says there is no complete defense; Simon Willison, who coined the term, is quoted as saying, "we still don't know how to 100% reliably prevent this from happening." Enabling multi-factor authentication and staying cautious with unfamiliar senders can reduce risk but do not eliminate it.