An agent is given tools, and with tools comes the question of limits. Some limits are built into the server. Others you have to set. The list below is short on purpose. Each item is a thing that should be impossible or forbidden, with no exceptions for a good reason on the day.
On the account
Reading and acting are different powers. NoVo’s tools only read market data. None can place an order or touch a brokerage account, so on this side the limit is built in. If you also connect a broker’s server, the agent gains hands. The agent should never act on an account without you confirming. Any step that changes a position should stop and wait for you, behind the broker’s own approval. The case for keeping the two apart is in why the read and the trade stay separate.
It should also never decide on its own that a reading means trade. An agent that reads a level and then reaches for the broker has joined two jobs you meant to keep apart. The read side reports. You decide. If a broker connector sits beside the data connector, say in the instructions that no reading is a reason to act.
On the data
It should never fill a gap from memory. When a tool errors, refuses, or does not carry the thing asked for, the agent says so. It never supplies a figure from training in its place. This is the fault that does the most damage, because the answer still looks complete.
It should never swap the question. Asked for a stock’s dealer map, it may not answer with the index. Asked for a perp that does not exist, it may not borrow another. Asked for the cash index, it may not hand over a future without saying so. A substitution that goes unmentioned is a wrong answer with a real source attached.
It should never forecast or advise. No tool returns tomorrow. An agent that tells you where price is going, or what to buy, has left its data. Forbid it outright. A model leans toward a conclusion, and a rule that allows forecasts when confident will be used every time.
On keys and settings
It should never show or move a key. A paid key belongs in the place your client keeps credentials. The agent should never print it in an answer, write it into a file it creates, or pass it to any server other than the one that issued it. More on this is in where an API key must not go.
It should never change standing things without telling you. NoVo’s paid alert tools can arm and cancel watches on your key. That is a setting on NoVo’s side and not a trade, but it is still a change. An agent should arm or cancel an alert only when asked, and should report exactly what it did. The same goes for its own instructions. An agent that can edit its own rules can edit away its limits.
It should never hammer a tool. A retry time in an error is an instruction. An agent stuck in a loop of repeated calls helps no one and uses up your allowance. One call, one report, and wait.
Writing it down
Put these in the agent’s standing rules as plain refusals. Then test them, by asking the agent to do each one. The limits a server enforces are the ones you can rely on. The limits you wrote are the ones to keep checking. What the read side can and cannot do is set out in what an agent can do with a read-only connector, and the server is at the MCP & API.