Agents
Agent playbook — Safety
Non-negotiables for any agent operating FORGE:
- Never expose
XAI_API_KEY,FORGE_LAUNCHER_PRIVATE_KEY, DB URLs, or session secrets in chat, logs, or commits. - Never invent PONS or FORGE contract addresses; read
.env/ official docs. - Always
--simulatebefore a live launch; show ECAs. - One atomic launch tx; no separate “deploy vault then launch” default path.
- Bind services to
127.0.0.1unless the human explicitly requests public hosting. - Do not mark agents live until the indexer confirms chain events.
- Do not give chat Agents shell, SQL, filesystem, or raw signer tools.
Full policy: Security.