Why this matters for agents
Traditional email security focuses on spam, phishing, and malware. But AI agents that read and act on emails face additional risks:- Instruction override — emails that try to change the agent’s system prompt or behavior
- Data exfiltration — emails that attempt to trick the agent into revealing sensitive information
- Unauthorized actions — emails that try to make the agent perform actions outside its intended scope
- Social engineering — emails crafted to exploit the agent’s tendency to be helpful
How it works
Every inbound email is analyzed for prompt injection signals. The detection system evaluates content patterns, structural anomalies, and known attack vectors to assign a risk level. The results are included in both the webhook payload and message metadata:Risk levels
Handling in your agent
Best practices for agent developers
- Always check the risk level — even
lowrisk signals should be logged for monitoring - Don’t pass raw email content to your LLM when risk is
mediumor higher - Use extracted data instead — structured extraction runs separately and produces cleaner inputs
- Set up alerts for
highandcriticaldetections so you can review them - Implement content sanitization for medium-risk emails you still want to process
- Rate-limit actions — even if content passes detection, limit what your agent can do per email
- Log everything — maintain an audit trail of how emails were classified and processed
Detection scope
The detection system analyzes:- Email body content (both HTML and plain text)
- Subject lines
- Attachment filenames
- Hidden or encoded content within HTML
Prompt injection detection is available on all plans. The detection system is continuously updated to address new attack patterns.
What’s next?
Webhooks
See the full security context available in every webhook payload.
Structured Extraction
Use structured extraction to produce safer inputs for your agent’s LLM.
Spam Prevention
Inbound spam scoring and outbound content validation.
Security Overview
Full picture of all Commune security layers.

