Claude’s Gmail controls expose users to email errors and prompt injection
Anthropic’s assistant can sort Gmail and send messages on a user’s behalf, but Engadget says users should keep approval requirements active.

Anthropic’s Claude can reportedly manage Gmail inboxes by sorting messages and sending, replying to or forwarding emails on a user’s behalf. The capability can operate without approval if the relevant setting is enabled, increasing the consequences of mistakes.
Engadget identified several potential risks, including Claude inserting hallucinated information into an email, misunderstanding a request or sending a message before the user has reviewed it. The assistant can also reportedly trash or archive emails, although it cannot permanently delete them.
Incoming messages create a separate prompt-injection risk. Hidden text, such as white-on-white writing or text rendered at zero size, could contain instructions intended to redirect Claude’s behaviour. Engadget reported that such attacks could be used to monitor Gmail or extract information, including verification codes.
Privacy is also a concern when an AI assistant is given access to inbox data. Simon Willison, who coined the term “prompt injection”, said there is no known way to prevent the technique with complete reliability.
The report recommends keeping Gmail’s “ask before sending” setting enabled so users can review actions before they are carried out. It also advises giving Claude specific instructions and remaining cautious with unfamiliar senders, while using multi-factor authentication on other accounts.