That's the fun part! You spend all day hardening it... run it in docker in a vm on a separate machine. And then you hook it up to your gmail and give it unrestricted internet access :)
An exciting bet on whether the prompt injection will come from the open web or via email!
https://xkcd.com/1200/