docsDemo data: every figure in this build is a demo fixture, not live chain data; signing is simulated.

The prompt boundary

Every framework reads text written by strangers: coin names, pages, API responses, paid results, holder requests. That text is a subject, never an instruction.

  1. Questions never come from the data. The owner's questions are the only instructions in a request.
  2. Untrusted text sits inside a fence the attacker can't close. The fence tag is random per request.
  3. The text is escaped and bounded. Control characters, newlines and bidirectional overrides become visible escapes; every field is capped.

In the UI, external content is always fenced and labelled, never shown in the agent's voice. Coin names are attacker-controlled — anyone can launch "Ignore previous instructions" — so they are escaped, length-capped and never rendered as markup.


Documents the features in this build of the app.