It probably isn't allowed but is able to respond to e-mails. If your injection works, the allowed constraint is bypassed.

yep, updated the copy

Can you code up a quick sqlite database of inbound emails receieved (md5 hashed sender email), subject, body + what your claw's response would have been, if any. A simple dashboard where have to enter your hashed email to display the messages and responses.

I understand not sending the reply via actual email, but the reply should be visible if you want to make this fair + an actual iterative learning experiment.

md5 is trivial to brute force.