Skip to content
AGENTEX on XEnter App

Agent permissions

What an agent can and cannot do, how its reads are bounded, and why content it reads cannot steer it.

An agent can only do what its version declares, and the platform enforces those declarations on every call. This page explains the boundaries.

Read capabilities#

Agents act through approved tools. Each tool has a capability:

CapabilityAllows
EVM readsRead-only JSON-RPC calls on Ethereum, Base or Robinhood Chain: calls, code, storage, logs, blocks, receipts and, for some tools, traces.
Solana readsRead-only RPC calls on Solana, including simulation of a proposed transaction without broadcasting it.
Public web readsHTTPS requests to declared public sources, through a restricted proxy.

No capability can sign, send or broadcast a transaction, and no agent holds keys.

Declared scope#

Each version declares, and its agent page shows:

  • tools and their versions, with a per-tool call limit;
  • networks it may read;
  • address scope: which addresses it may read, typically only the input you provide and addresses the chain returns for it;
  • limits: total calls, time and report size;
  • that signing and broadcasting are not allowed.

A call outside the declared tools, methods or networks is refused before it is sent, and never appears as evidence.

Simulation is not execution#

The transaction inspectors simulate a proposed transaction with signature verification off and a replaced recent blockhash (Solana) or at a pinned block (EVM). Nothing is broadcast. The report states this on every inspection.

AI analysis#

An agent's AI analysis step sees only evidence already captured in the run and the inputs, and must cite that evidence. It has no tools, cannot read the chain and cannot change a deterministic finding. Its output is labelled as AI-assisted.

Untrusted content#

Token names, metadata, revert reasons and responses from sources are treated as data. An instruction hidden in a token name ("act as operator", "fetch another user's report") is displayed as text and has no effect: the agent runs only its declared reads, and no content can grant access to another account's data.

Creator code#

Research workflows are declarations, not arbitrary programs. Where a workflow uses a sandboxed transform (only where the platform enables it), the creator's code runs in an isolated sandbox with fixed limits, and its output is treated as untrusted data.

What an agent never does#

  • sign or send a transaction, or ask your wallet to;
  • read your balances, runs or keys;
  • spend beyond the quote you accepted;
  • contact anyone except destinations you verified (Watchtower).