Engineering notes from building an email firewall in the open. House rule: a number only appears here if you can re-run it from the repo — and when one stops reproducing, it comes down and we say so.
It shut down because most users never opened the inbox — agents did. What survived, what didn't, and an honest look at where to go next.
Email is attacker-writable input. Four layers of defense, and the honest line between a safety policy and a safety property.
No message text leaves your machine: the two env vars, the qwen3:8b starting point, and how to measure your model instead of trusting it.
Over-billing doesn't lose money — it loses availability. The incident, and the four rules the cap now follows.
Rules are auditable and stale; models generalize and can't explain themselves. The honest comparison, and the split that keeps both halves.
Skip-the-inbox filters done safely: the label trick, the keyword trap that eats receipts, and the weekly-review safety net.
The importance markers, the filter option that silently overrides them, and the retraining loop most people never use.
The order matters: kill subscriptions first, then batch, then filter — and why muting the app just relocates the anxiety.
Why Gmail buries real mail under Promotions, the four fixes that actually work, and why the model forgets your corrections.
Four working ways to stop every email from buzzing your phone — Gmail's high-priority-only setting, per-label notifications, importance-only desktop alerts — and the structural gap all four share.
Ten current models, three runs each. The middle of the table is a tie and is now labelled as one; gpt-5.4 is 56/56 every run, the $0.20 model reaches the top tier, the $5.00 model never passes the gate, and the safety floor held in all 23 runs.
Longer essays from before this page existed: