Limits live in code and on-chain — not in a prompt. Even a fully prompt-injected model cannot exceed your budget, trade in a group, or touch a honeypot. Here's every layer.
Within budget, small size, clean security scan, reliable oracle. Executes under the session key without asking.
Bigger size, higher price impact, or heuristic warnings. The bot shows the full proposal — contract address included — and waits for your ✅.
Honeypot, failed sell simulation, ticker scam, over budget, group chat, expired session, unreliable oracle. Nothing — not you, not the model — can push it through.
{{ l.b }}
Official stock tokens resolve through a verified registry. A token calling itself "NVDA" at any other address is flagged as a scam — automatically, before any price is quoted. Token names and descriptions are treated as data, never as instructions, so embedded prompt-injection text gets reported instead of obeyed.
Revokes every active session immediately. No confirmation, no cooldown. Session keys deleted.