Keep the model away from keys and arbitrary payment recipients.
Policy before signing
The included policy engine checks stale observations, chain ID, available balance, gas and reserve floors, locked program funds, daily budgets, slippage and price impact. It accepts a small action enum and rejects unrecognized actions.
Recipient control
Buybacks use reviewed venue adapters and the treasury as recipient. Transfers to a fixed burn destination and actual totalSupply reduction are recorded separately. The independent platform pool requires exact whole-transaction supply reduction. Holder distributions need a finalized snapshot, a Merkle root and proofs. A model-supplied payout address is rejected.
Outside evidence
Web pages, post text and browser content are untrusted inputs. They cannot change model instructions, execution adapters or spending limits. Text filtering reduces accidental instruction mixing; it is not a complete prompt-injection defense.
Flap's platform authority
Flap documents guardian and admin permissions, including changing the market wallet for some taxed-token versions. An ordinary BNB receiver does not require Vault Guardian methods. Choosing a spec-compliant Flap Vault requires irrevocable equivalent guardian permissions; a low-risk badge additionally requires exclusive guardian beacon-upgrade authority. awake must disclose these platform permissions separately from the treasury's own controls.
Execution is off
The preview does not hold signing keys. The contracts and deployment scripts are source deliverables; they have not been deployed or independently audited. Production signing belongs in an isolated service with RPC simulation and receipt verification.
Flap permission reference ↗
AWAKE