Merchant allowlist
Only named vendors may ever be paid; everyone else is FLAGGED.
How to configure it
In sipi.bot: allow: [openai.com, stripe.com]. Once set, every transaction matching the
causes below is BLOCKed or FLAGged
before any money moves.
Prompt-injected purchases at unknown or malicious merchants.
3 incidents this rule would have stopped
| Incident | Loss | Cause | Year |
|---|---|---|---|
| OpenAI charged $1,200 past a configured $50 hard limit | $1,200 | Caps that didn't enforce | 2025 |
| Account billed $1,100 after hard monthly cap was removed | $1,100 | Caps that didn't enforce | 2025 |
| Fake bug report tricked an agent into leaking a live AWS key | Cost not disclosed | Prompt injection | 2025 |
Configure this rule in sipi.bot
The pre-spend firewall evaluates every agent transaction in <5ms. Set this rule once and it runs on every proposed charge, forever.