The Burrito Problem (a solution)
Kyle Kingsbury joked an AI agent might get talked into a $950 grandmother burrito by El Farolito's chatbot. I think he was being optimistic. So I built a working prototype where the boundaries live in a signed token between the LLM and the execution layer, not in the prompt.