F FORGE
FORGE AGENT

Agents

Agent playbook — Safety

Non-negotiables for any agent operating FORGE:

  1. Never expose XAI_API_KEY, FORGE_LAUNCHER_PRIVATE_KEY, DB URLs, or session secrets in chat, logs, or commits.
  2. Never invent PONS or FORGE contract addresses; read .env / official docs.
  3. Always --simulate before a live launch; show ECAs.
  4. One atomic launch tx; no separate “deploy vault then launch” default path.
  5. Bind services to 127.0.0.1 unless the human explicitly requests public hosting.
  6. Do not mark agents live until the indexer confirms chain events.
  7. Do not give chat Agents shell, SQL, filesystem, or raw signer tools.

Full policy: Security.