Operate
Security Requirements
Threat boundaries
Treat all of these as untrusted:
- browser input
- creator prompts/personality text
- LLM tool arguments
- public URLs and fetched documents
- RPC providers
- event data until chain/reorg checks pass
- uploaded images/files
- third-party contract metadata
Keys and secrets
- User launches are signed in user wallets.
- CLI launch key is only loaded by the CLI process/environment, not web/API workers.
- Platform recipient should be a multisig, not a hot EOA, once real value exists.
- xAI key is API/worker-only.
- Mobula Enterprise key is API/worker-only; TradingView datafeed and swap UI must proxy through FORGE — never embed the key in the browser.
- Validate Mobula swap
toagainstMOBULA_ROUTER_ALLOWLISTbefore returning calldata to clients. - DB/Redis are localhost/private only.
- never log private keys, auth headers, session secrets or full
.env. - rotate secrets after any accidental exposure.
AI isolation
- no arbitrary shell/filesystem/SQL/HTTP tool
- typed allowlisted tools only
- strict Zod/JSON-schema validation
- tool-specific authorization separate from LLM instruction
- hard cap tool recursion/steps
- state-changing tools are idempotency-keyed and never automatically retried after an ambiguous timeout
- external tool output is marked untrusted
- identity generation is platform-server-only; never expose xAI keys or raw provider URLs that embed credentials
- download Imagine outputs server-side; serve FORGE-hosted avatar URLs only
- identity seeds screened for abuse / IP impersonation; generated personality remains untrusted creator config
Web security
- secure HttpOnly SameSite session cookies
- CSRF protection for authenticated cookie mutations
- CSP tuned for Next.js/wallet providers
- sanitize rendered markdown
- prohibit
javascript:URLs - upload MIME sniffing and max size
- wallet signature nonce is one-use + expiring + domain bound
- request IDs and audit trails
SSRF
If Agent knowledge supports fetching URLs:
- only HTTP/HTTPS
- resolve DNS and reject RFC1918/loopback/link-local/metadata ranges
- revalidate redirect destinations
- limit redirects/body size/time
- optional outbound domain allowlist
Chain security
- validate chain ID on every signer flow
- checksum/validate addresses
- live-read PONS configuration before launch
- human-readable launch preview
- transaction value ceiling
- slippage protection for trades (Mobula quote + server max BPS)
- reorg-aware indexer
- unique
(tx_hash, log_index)processing
Contract security
Before real value:
- Foundry unit tests
- fuzz split invariants
- reentrancy tests with malicious beneficiary contracts
- unusual ERC-20 transfer behavior tests
- PONS escrow integration fork tests
- independent review/audit
Invariant examples:
- platform + beneficiary amount == gross
- caller cannot alter either recipient
- caller cannot select platform BPS
- no unprivileged path can withdraw to third party
Rate/abuse controls
- Nginx edge rate limiting
- Redis per-wallet/IP/Agent limits
- launch intent expiration
- chat spend budget by Agent/day
- max concurrent streams
- admin kill switch for chat generation (does not block chain data)
Operational security
- Ubuntu automatic security updates or patch cadence
- SSH key auth only
- Fail2ban
- UFW only 22/80/443
- DB backups encrypted off-host
- health alerts
- dependency lockfile + vulnerability scan in CI
- separate staging and production envs
Release gates
Do not enable public Launch until:
- contracts reviewed
- PONS live addresses verified
canLaunchbehavior tested- indexer reorg test passes
- RPC failover test passes
- fee split test passes with native + approved ERC-20 quote asset
- Agent prompt injection/tool abuse test passes
- restore from DB backup tested
- PM2 reboot recovery tested
- production rate limits and monitoring are active