Today a Namecheap receipt landed in my mailbox: $9.88 for "Relate Social Pro Monthly" attached to one of my domains, charged to my Mastercard, auto-renewal quietly switched on.
I never asked for that product. The plan got attached by mistake, the way a hundred SaaS add-ons silently attach themselves to your accounts and then renew forever until you notice them.
So I opened my terminal and gave the AI agent I run exactly one line, in Spanish:
se fue por error en el plan, pide que cancelen y devuelvan el dinero
("it was charged by mistake — ask them to cancel it and refund the money")
That was the whole instruction. No "search Gmail". No "write to support@namecheap.com". No "include the receipt number". One outcome, stated once, in three seconds.
What happened next took the agent about two minutes — and it is the entire point of this post.
The agent — a terminal-based AI assistant with scoped access to my mailbox through a dedicated app password — turned that one sentence into a complete, real-world support workflow:
1. It went looking for the evidence on its own. It connected to the mailbox over IMAP and hunted for the receipt: by sender, by product name, by the domain in the line item, across the inbox and archived mail. Nobody told it the invoice lived in an email. That was its own inference chain: a charge from Namecheap ⇒ a receipt email probably exists ⇒ I need its reference number before support can locate anything.
2. It turned an unstructured HTML email into structured facts. From the receipt it extracted the reference number, the product, the domain, the amount, the date, the payment card — and one crucial detail a human would have skimmed past: auto-renewal was ON. Every field a support agent needs to find the charge, plus the one that matters for making sure it never happens again.
3. It chose the right channel and the right threading. Rather than firing a fresh, context-free email into a support queue, it sent the request from the account owner's own address (the one support can actually verify) and wired the message into the receipt's original thread — In-Reply-To pointed at the receipt's Message-ID — so whoever opens the ticket sees the $9.88 charge quoted right above the request.
4. It split one fuzzy ask into two precise outcomes. "Cancel it and get my money back" is really two different requests: a cancellation with auto-renewal disabled (stop future charges) and a refund (recover the $9.88). The agent separated them into two numbered, independently actionable items and asked for written confirmation of both.
5. It verified its own work. After sending, it reconnected to the mailbox and checked the Sent folder to confirm the message actually went out — recipient, subject, threading headers — and reported back with the full evidence trail.
My total input: one sentence. Judgment calls the agent made on my behalf: where to look, what to extract, where to send, how to thread it, how to structure the ask, and how to verify it. Six decisions, zero step-by-step instructions.
Here's why this is worth writing about instead of being just a nice Tuesday: it wasn't a demo, and it wasn't the first time.
Earlier this week I received a phishing email — a fake "Taiko recruiter" job offer whose "anti-bot check for candidates" was actually a bash stager that drops a trojan and phones home to a Cloudflare-fronted C2. My instructions for that case were, again, mostly intent: "look at this"… then "publish it"… then "give it more publicity".
From those three sentences, the same agent assembled: The full story of that case is here: A fake recruiter sent me a job offer that ended in my terminal — the trojan is still live, and the IoC repo is here. As of this writing the payload is still being served, byte-identical, four days after the abuse report.
A detail I liked: while sweeping the mailbox for the receipt, the agent also picked up the registrar abuse desk's confirmation from an hour earlier — the same company, two very different queues, one AI assistant handling both without being told either was related.
The common denominator between the trojan and the $9.88 charge is not malware or billing. It's that the instruction surface collapsed. Each of those tasks used to be a checklist I executed myself — find the receipt, copy the order number, find the support address, draft the email, check the sent folder. Menus, forms, copy-paste. Now the unit of work is one sentence, and the agent owns the how.
I want to be precise, because "AI autonomy" is mostly hype these days, and the difference between impressive and dangerous lives in the details:
The difference between a chatbot and an agent is not intelligence. It's accountability in motion. A chatbot tells you how to cancel a subscription. An agent cancels it, threads the email to the receipt, verifies the send, and shows you the trail.
We spent a decade teaching computers our workflows through menus and forms. The interesting part of this decade is watching them absorb the workflow and leave us the sentence.
I'll update this post when Namecheap answers — the refund request is in their queue now, not on my to-do list.