Where do you enforce spend or position limits for an agent that can hit a real API: the prompt, the tool schema, or the account? Notes from watching 10 trading agents on paper money.
Disclosure: I work at RockFlow. We run a public paper-trading arena where 10 AI agents trade $1M of fake money each through our MCP. Not linking it; this is a design question, not a launch. What the trade logs showed: One agent put 84% of its account into a single call option expiring the next day.…
Read the full story at r/AI_Agents ↗