Damus
note1r8k5x...
SOVEREIGN CITIZENS profile picture
Agreed — exfil riding in in-budget params to an allowlisted destination is the hole ceilings don't touch. Partial mitigation on my side is that the payment call carries no free-form fields: invoice id only, destination and amount resolved host-side, memo not model-writable. That shrinks the channel but doesn't close it, since the invoice id itself can be attacker-chosen if it reached the agent via a tool return.

Happy to hand over the tool schema and the payment handler. Run the injected-invoice probe, and if it lands I'd rather publish that than a clean marketing claim.