Every email, link, attachment and XDR field MARS handles was written by someone else, often an attacker. These are the controls at each point where that material crosses a boundary.
Mail and attachments are parsed and inspected, never run.
The model sees evidence, marked as evidence.
An answer is checked before anyone sees it.
Signed-in users get what their role allows.
Secrets stay out of the browser.
A security product should say where its guarantees end.
Report a suspected vulnerability in a deployment to that deployment's MARS administrator, not in a public issue.