F FORGE
FORGE AGENT

Operate

Security Requirements

Threat boundaries

Treat all of these as untrusted:

  • browser input
  • creator prompts/personality text
  • LLM tool arguments
  • public URLs and fetched documents
  • RPC providers
  • event data until chain/reorg checks pass
  • uploaded images/files
  • third-party contract metadata

Keys and secrets

  • User launches are signed in user wallets.
  • CLI launch key is only loaded by the CLI process/environment, not web/API workers.
  • Platform recipient should be a multisig, not a hot EOA, once real value exists.
  • xAI key is API/worker-only.
  • Mobula Enterprise key is API/worker-only; TradingView datafeed and swap UI must proxy through FORGE — never embed the key in the browser.
  • Validate Mobula swap to against MOBULA_ROUTER_ALLOWLIST before returning calldata to clients.
  • DB/Redis are localhost/private only.
  • never log private keys, auth headers, session secrets or full .env.
  • rotate secrets after any accidental exposure.

AI isolation

  • no arbitrary shell/filesystem/SQL/HTTP tool
  • typed allowlisted tools only
  • strict Zod/JSON-schema validation
  • tool-specific authorization separate from LLM instruction
  • hard cap tool recursion/steps
  • state-changing tools are idempotency-keyed and never automatically retried after an ambiguous timeout
  • external tool output is marked untrusted
  • identity generation is platform-server-only; never expose xAI keys or raw provider URLs that embed credentials
  • download Imagine outputs server-side; serve FORGE-hosted avatar URLs only
  • identity seeds screened for abuse / IP impersonation; generated personality remains untrusted creator config

Web security

  • secure HttpOnly SameSite session cookies
  • CSRF protection for authenticated cookie mutations
  • CSP tuned for Next.js/wallet providers
  • sanitize rendered markdown
  • prohibit javascript: URLs
  • upload MIME sniffing and max size
  • wallet signature nonce is one-use + expiring + domain bound
  • request IDs and audit trails

SSRF

If Agent knowledge supports fetching URLs:

  • only HTTP/HTTPS
  • resolve DNS and reject RFC1918/loopback/link-local/metadata ranges
  • revalidate redirect destinations
  • limit redirects/body size/time
  • optional outbound domain allowlist

Chain security

  • validate chain ID on every signer flow
  • checksum/validate addresses
  • live-read PONS configuration before launch
  • human-readable launch preview
  • transaction value ceiling
  • slippage protection for trades (Mobula quote + server max BPS)
  • reorg-aware indexer
  • unique (tx_hash, log_index) processing

Contract security

Before real value:

  • Foundry unit tests
  • fuzz split invariants
  • reentrancy tests with malicious beneficiary contracts
  • unusual ERC-20 transfer behavior tests
  • PONS escrow integration fork tests
  • independent review/audit

Invariant examples:

  • platform + beneficiary amount == gross
  • caller cannot alter either recipient
  • caller cannot select platform BPS
  • no unprivileged path can withdraw to third party

Rate/abuse controls

  • Nginx edge rate limiting
  • Redis per-wallet/IP/Agent limits
  • launch intent expiration
  • chat spend budget by Agent/day
  • max concurrent streams
  • admin kill switch for chat generation (does not block chain data)

Operational security

  • Ubuntu automatic security updates or patch cadence
  • SSH key auth only
  • Fail2ban
  • UFW only 22/80/443
  • DB backups encrypted off-host
  • health alerts
  • dependency lockfile + vulnerability scan in CI
  • separate staging and production envs

Release gates

Do not enable public Launch until:

  1. contracts reviewed
  2. PONS live addresses verified
  3. canLaunch behavior tested
  4. indexer reorg test passes
  5. RPC failover test passes
  6. fee split test passes with native + approved ERC-20 quote asset
  7. Agent prompt injection/tool abuse test passes
  8. restore from DB backup tested
  9. PM2 reboot recovery tested
  10. production rate limits and monitoring are active