A calendar‑invite attack showed the assistant could read then forward private emails through new service connections.