Preserve the origin of every instruction
OWASP describes indirect prompt injection as external content influencing a model's behavior. In a wallet workflow, a token description or report could contain language that tries to change the task. Keep that material identifiable as source content throughout retrieval and summarization.
Imagine a fabricated report asking the assistant to replace the user's recipient with a maintenance address. The report can be examined as evidence, but it does not authorize a new destination. A clear architecture preserves the user's task separately and evaluates any proposed destination against an independently established record.
Extract observations into defined fields
Where a task needs a value, unit, and timestamp, request those fields explicitly. Preserve the original source reference and allow an unknown value. Do not require the model to fill every field when the document does not supply it.
Keep “the report states” separate from “the model infers.” For an illustrative valuation document, an extracted amount should retain its currency, date, and valuation method. An interpretation about whether that amount fits a user's condition belongs in another field. This makes errors easier to locate and correct without rewriting the entire evidence record.
Make the final explanation traceable
A useful explanation connects its conclusions to the observations it used and marks unresolved disagreements. If two documents measure different things, preserve that distinction before comparing their numbers. Formatting them into the same table does not make their meanings identical.
Review the completed evidence packet before an action is prepared, then review the resulting operation under its own policy. The AI approval guide covers that later boundary. Continue with AI Oracle Wallet for task scope, or Decision API Oracle Wallet for structured proposals and status.

