Lesson 3 of 4
Permissions and safety
Every command needs macOS's Automation permission. Past opening windows, a command also needs one of two switches in Briskmail's Settings. Both are off until you turn them on, and no command can turn them on for itself.
macOS: Automation
macOS asks you once per program whether it may control Briskmail. That answer covers everything running inside the program, so allowing Terminal allows every script you run in Terminal. Change it in System Settings ▸ Privacy & Security ▸ Automation.
With that alone, an agent can open a conversation, a search or a folder, check for new mail, and fill in a compose or reply window. You still read the window and click Send.
Works with Automation consent
BuiltNo switch. macOS asks you once whether the program running the command may control Briskmail.
Opens things in Briskmail's window: a conversation, a search, a folder, a prefilled compose or reply window. With reply --send, the separate auto-send switch and Touch ID grant apply. These commands never print mail contents.
When macOS says no, the command stops before Briskmail sees it. Every command reports what happened with one of four exit codes, and code 2 also covers a switch that is off:
| Code | Meaning |
|---|---|
| 0 | Done. |
| 2 | Not allowed: macOS refused Automation for the app you ran it from (-1743), or this command's switch is off. The message names the switch. |
| 3 | Briskmail reported an error, printed on stderr. |
| 64 | Bad usage. |
Briskmail: two switches
Both live in Settings ▸ Advanced ▸ Command-line access, and both start off.
- Let apps read and organize my mail lets a command list, search and read your mail, and do the things you can undo in the app.
- Let apps send without asking lets a command send mail without you clicking Send.
No command and nothing in Briskmail's AppleScript dictionary can change a switch, so an agent can't turn on its own access. A command whose switch is off exits with code 2, the same "not allowed" code as a refused Automation prompt, and the message names the switch to turn on.
Read and organize
This one switch covers reading bodies, so turn it on knowingly. Once your agent can read a message, the sender has written part of its prompt. The prompt injection lesson covers what that means.
Read and organize
Coming soonSwitch: Let apps read and organize my mail, in Settings ▸ Advanced ▸ Command-line access. Off until you turn it on.
Lists, searches and reads your mail, and does the things you can undo: label, mark read or unread, star, archive, snooze, and save a draft without opening a window.
- List and search rows carry the id, thread id, sender, subject, date, labels and unread state. No snippet and no body.
- Answers come from the copy of your mailbox already on your Mac when it has them.
- Reading a body is where a hostile email can reach your agent. Text a reader would not see is removed first: hidden elements, text coloured like its background, very small text, zero-width characters and HTML comments.
- Body text is wrapped in untrusted_email_content, in text and in --json, so your agent can tell mail apart from your instructions.
- Removing hidden text lowers the odds of an injected instruction getting through. It is not a guarantee.
- Label, archive, star and the rest go through the same code as the buttons in the app, so Undo works the same way.
triage list search unread labels accounts read thread attachments label unlabel mark-read mark-unread star unstar archive snooze save-draft
Send without asking
This is the only way mail leaves without you clicking Send, which is why it has the most rules. The one to remember: a new address is never sent to. It becomes a draft and a notification, and the agent is told so.
Send without asking
BuiltSwitch: Let apps send without asking, in Settings ▸ Advanced ▸ Command-line access. Off until you turn it on.
Lets an agent send mail while you are away. Turning it on takes Touch ID or your login password.
- The grant lives in your Keychain, not in a settings file, so a program that can write files still cannot turn it on.
- Only to people the account already knows: someone in the thread, in Contacts, or someone you have written to. Any new address turns the message into a draft and a notification.
- Each send waits 20 to 30 seconds in Undo Send, with a notification that offers Undo.
- About 20 sends an hour per account. Past that, messages are saved as drafts.
- Every send carries the Gmail label Briskmail/Sent by agent and shows in Window ▸ Activity.
briskmail sendbriskmail send --to new@unknown.example --subject Hello --body "Can we talk?"
held-as-draftAn address the account has never written to: saved as a draft, nothing sent.
Never, with any switch
- Permanently delete mail
- Create or change filters or forwarding rules
- Change account or security settings
- Unsubscribe