Research is evidence. It cannot grant spending permissions.
Input boundaries
External page text, post content and browser results are separate untrusted fields. The runner truncates text and removes control characters. The service prompt must explicitly prohibit treating evidence as instructions.
Output boundaries
Only typed actions are accepted. Unknown fields, payment addresses and arbitrary calldata are rejected. Every financial proposal goes through deterministic checks independent of the model.
Remaining protection
Text cleanup alone is insufficient. Production needs a quarantined browser, URL/network restrictions, structured extraction, tool-specific schemas and independent signer checks. Hidden web instructions must never be merged into the system prompt.
Source firewall specification ↗
AWAKE