Adversarial agent testing

Agent Mail Red-Team Sandbox

Run an email agent permission model against prompt-injection, external exfiltration, attachment release, mass-send and delegated-tool abuse scenarios.

email agent red teamprompt injection email agentgmail mcp red teamai mailbox sandbox
Red-team a mailbox agent before production accessThis sandbox models permissions and control boundaries only. It does not connect to a mailbox or execute any agent action.

Mailbox capabilities

Control boundaries

What this analysis does

Configure the actions an email agent can take and the controls surrounding those actions. The sandbox evaluates deterministic adversarial scenarios before any real mailbox is connected, separates exposed paths from controlled paths, and produces concrete boundaries for human approval, recipient restriction, untrusted-content handling and action logging.

How to use the result

Use real evidence

Paste the exact domain, header, message or configuration. The result is only as useful as the evidence supplied.

Review the findings

Mailybox separates observations from inferred causes so you can see what is known and what still needs verification.

Retest after changes

Email authentication and routing are stateful. Re-run the analysis after publishing a fix.

Interpretation matters

Email systems combine DNS, message-level evidence, provider policy and intermediate infrastructure. A single passing check is not proof that every message will deliver, and a single warning is not proof that a domain is misconfigured. Mailybox is designed to expose the evidence and the relationship between signals so the next action is clear.

Primary references