You pass an open api spec on creation. You can remove all methods you fear may be risky, and leave it enough so that he can read your emails or calendar, if you feel comfortable with that
The crazy thing is there is no code! The instructions are just “you are a helpful email assistant. You search the user’s gmail in response to their questions” and you just paste in the OpenAPI spec and OAuth details for gmail into the GPT maker form. I asked GPT-4 to write the OpenAPI spec for the gmail API’s necessary to search my inbox.