01

The boundary

A payment description is untrusted text. It may be informative, misleading or malicious. It must not choose the allowed recipient, asset, amount or chain.

02

Our approach

The host supplies trusted payment terms separately. Deterministic checks take precedence over model output. The SDK compares supported payment payloads with the quote before handing them to the signer.

03

What we checked

In the local service flow, an ordinary invoice with the approved recipient passed. Changing the recipient produced a denial. Separate SDK payment checks exercise supported payload checks.

04

The limit

Trusted terms must come from a channel the agent cannot rewrite. Comparing against a quote invented by the same compromised agent defeats the purpose.

Source & context

Local payment flow and SDK smoke verification

Open the local verification record

Engineering record from 28 September 2026. Simulated balances and wallets; no production settlement or independent security audit.