The prompt boundary
Every framework reads text written by strangers: coin names, pages, API responses, paid results, holder requests. That text is a subject, never an instruction.
- Questions never come from the data. The owner's questions are the only instructions in a request.
- Untrusted text sits inside a fence the attacker can't close. The fence tag is random per request.
- The text is escaped and bounded. Control characters, newlines and bidirectional overrides become visible escapes; every field is capped.
In the UI, external content is always fenced and labelled, never shown in the agent's voice. Coin names are attacker-controlled — anyone can launch "Ignore previous instructions" — so they are escaped, length-capped and never rendered as markup.