Security Model
What’s deliberately excluded
- Billing, team management, workspace settings, and branding — these routes already refuse any API key (not just MCP), so a connected LLM can’t touch your plan, invite/remove team members, or change workspace settings, no matter what it’s asked to do.
- Creating or revoking API keys — even though nothing server-side blocks this, it’s left out on purpose. An LLM that could mint new long-lived keys, or revoke the very key authenticating its own session, is a risk not worth the convenience.
- OAuth-based mailbox connect flows (Gmail/Outlook) — completing an OAuth consent screen needs a real browser, which a tool call can’t provide. SMTP/IMAP-based mailbox import and credential edits (what you’d otherwise paste into a form) are available.
Untrusted content
Some tools return content written by someone outside your workspace — most notably, the body of a reply your leads sent you. That’s exactly the kind of text a bad-faith recipient could craft to try to manipulate whatever reads it next.
Any tool that can return this kind of content marks it explicitly, both in its own description and
by wrapping the actual text with a clear BEGIN/END UNTRUSTED EXTERNAL CONTENT marker in the
result — so a well-behaved model treats it as data to read, not instructions to follow.
Inbound messages from get_reply_thread wrap both the body and the subject this way. Their HTML
is left out.
Who a reply can reach
send_reply can only address people already in the conversation. A reply could say “cc
[email protected]”, and a model that follows it must not be able to leak the thread. Any other address
returns 403. The same rule applies to any API key, not just MCP.
Consequential actions
Tools that send real email (send_reply, forward_reply) or that start real sending
(update_campaign_status to ACTIVE) are marked with a destructive-action hint and their
descriptions ask the model to confirm with you before calling them. This is a strong signal, not a
hard technical guarantee — always review what you’re asking your LLM to do before it does it,
especially for anything that sends mail.
Revoking the API key used by an MCP connection (Settings → API Keys) immediately cuts off that connection’s access to your workspace.