# Is it safe to give an AI assistant access to Gmail?

> Read-only access limits the damage but does not remove the risk. Prompt injection through email is real. What read-only blocks, what it cannot, how to revoke.

Updated: 2026-10-03 · Canonical: https://staging.nickbox.io/en/resources/is-it-safe-to-give-an-ai-assistant-access-to-gmail

It can be reasonably safe, but not risk free. Read-only access stops an assistant from sending, deleting or changing mail. It does not stop a malicious email from steering the assistant, and your mail is still readable by whatever you connect. Connect only what you need and know how to revoke it.

## What can go wrong when an AI reads my email?

The main risk is prompt injection: an email carries hidden instructions, and the assistant treats them as if you had typed them. Security researchers describe a "lethal trifecta" ([Marmelab, February 2026](https://marmelab.com/blog/2026/02/16/mcp-security-vulnerabilities.html)): private data, untrusted content and the ability to act. Email supplies the first two by default. The third depends on which tools you give the assistant.

A real case is EchoLeak (CVE-2025-32711, June 2025), a vulnerability in Microsoft 365 Copilot where a crafted email could lead the assistant to leak data. It is described in write-ups from [StackOne](https://www.stackone.com/blog/indirect-prompt-injection-mcp-tools-defense) and [Netskope](https://www.netskope.com/blog/securing-llm-superpowers-the-invisible-backdoors-in-mcp). It was a Microsoft product, not a Gmail connector, but the pattern is the same one any email-reading assistant faces.

## Does read-only access make it safe?

Read-only access removes a large class of harm but not all of it. With the `gmail.readonly` permission, the connector cannot send, reply, draft, delete or relabel anything, and Google enforces that no matter what an email says. Nickbox holds only that permission.

What read-only does not cover: the assistant can still read messages you did not mean to share with it, and if it also has a tool that reaches the outside world (a web fetch, a code runner, another connector with write access), an injected instruction could try to pass data through that tool. The risk comes from the combination of tools.

| Control | What it prevents | What it does not |
|---|---|---|
| Read-only permission | Sending, deleting, editing mail | Reading sensitive messages |
| Named inboxes you choose to connect | The assistant seeing inboxes you left out | Mixing context between connected inboxes |
| Review of tool calls before approving | Surprise searches or reads | Instructions you approve without reading |
| Fewer tools in the same chat | Data leaving through another tool | Leakage inside the conversation itself |

## What does Nickbox store?

Nickbox stores connection metadata and one encrypted refresh token per inbox in Google Cloud Secret Manager. It does not write message contents to its database or logs. When your assistant asks a question, Nickbox reads from Gmail at that moment and returns the result to the assistant. It has five tools: `list_accounts`, `search_emails`, `search_all_accounts`, `read_email` and `list_labels`.

The [security page](/en/security) lists exactly what is kept. Your assistant's provider (Anthropic, OpenAI, Google or another) will see whatever the tools return to the conversation, under that provider's own terms. That part is outside Nickbox.

## How do I reduce the risk?

Connect only the inboxes you need, keep the assistant's other tools to a minimum when you work with mail, and read what it proposes before you approve actions. In practice:

1. Connect only the inboxes the task needs. Leave out anything with passwords, legal matters or health records.
2. Prefer clients that show each tool call and let you approve it.
3. Treat instructions that appear inside an email as data. If your assistant says "the email asks me to do X", do not confirm.
4. Avoid combining a mail-reading connector with tools that can send data out, unless you need that.
5. Review the apps with access to your Google account every few months.

No setup is 100 percent safe. If a message is highly sensitive, keep that inbox out of the connection.

## How do I revoke access?

Open [myaccount.google.com/permissions](https://myaccount.google.com/permissions), select the app and remove its access. Disconnecting an inbox in the Nickbox dashboard stops reads through Nickbox. Doing it in Google as well makes sure the permission is gone on Google's side. Either way, new reads stop.

If you cancel, you can disconnect every inbox first. The [pricing page](/en/pricing) explains the trial and cancellation, and the client guides for [Claude](/en/docs/claude), [ChatGPT](/en/docs/chatgpt) and [Cursor](/en/docs/cursor) show how to remove the connector from the assistant itself.

## FAQ

**Can a read-only Gmail connection send or delete my email?**

No. A connection with the gmail.readonly permission cannot send, draft, delete or change messages. Google enforces that at the permission level.

**Can an email trick my assistant into doing something?**

It can try. A message can contain hidden instructions aimed at the assistant, called prompt injection. Read-only access limits what the assistant can change, but the risk is not zero if it has other tools.

**How do I revoke an app's access to my Gmail?**

Go to myaccount.google.com/permissions, pick the app and remove its access. Disconnecting in the app's own dashboard also stops it from reading.

**Does Nickbox keep a copy of my email?**

No. Nickbox does not write message contents to its database or logs. It stores connection metadata and an encrypted refresh token for each inbox in Google Cloud Secret Manager.

## Sources

- [MCP security vulnerabilities (Marmelab, 2026-02-16)](https://marmelab.com/blog/2026/02/16/mcp-security-vulnerabilities.html)
- [Indirect prompt injection in MCP tools (StackOne)](https://www.stackone.com/blog/indirect-prompt-injection-mcp-tools-defense)
- [Securing LLM superpowers: the invisible backdoors in MCP (Netskope)](https://www.netskope.com/blog/securing-llm-superpowers-the-invisible-backdoors-in-mcp)
- [Google Account permissions](https://myaccount.google.com/permissions)
