# Agents, wallets and cameras: staying in charge of your own

> An AI agent that reads the web, a wallet it can spend from, and a headset with cameras on your face each widen what can go wrong. A practical list of what to check, for people who use such tools and for people who build apps for them.

Michal Takáč, 7 October 2026 · Guides
Source: https://graspable.dev/blog/security-for-agents-wallets-and-headsets

Three things arrived in everyday software within about a year. Agents that act for you, wallets those agents can spend from, and headsets and glasses that see the room you are in. Each is useful alone. Together they mean that software you did not write can read what a stranger wrote, hold money, and look through a camera you are wearing.

This post is a checklist. It names no product, and it applies to any tool of this kind, ours included.

## Text an agent reads is not an instruction

An agent reads files, web pages, messages, tool results and other people's code. Any of them can contain a sentence addressed to the agent. OWASP lists this, prompt injection, as the first risk for applications built on language models, and says plainly that no complete fix exists.

What you can check in a tool:

- It asks before it runs a command or reaches outside your project, and the question shows the real command.
- A file that runs code, such as a build script, is treated like a command when the agent changes it.
- What it remembers between sessions is something you can read, edit and delete.
- Tools from a third party cannot declare themselves safe. You decide what runs without asking.
- A project you got from someone else is treated as a stranger's text until you have read it.

A habit that helps more than any setting: read the approval card. Most successful attacks on agents end with a person clicking yes.

## A wallet for an agent is a spending account

Give an agent a wallet the way you would give a teenager a prepaid card. The safest design keeps the key out of the model's reach entirely, so the model can ask for a payment and something else, with rules, makes it.

Before you fund one:

- Use a wallet made for the agent. Never your main wallet, and never a seed phrase you use elsewhere.
- Put in only what you accept losing.
- Set limits for one purchase, one task and one day, and confirm they are enforced by the program and not by the model's good sense.
- Prefer payments that authorise one exact transfer over approvals that let a contract spend up to a ceiling. [EIP-3009](https://eips.ethereum.org/EIPS/eip-3009) is an example of the first kind.
- Ask to be consulted when the reason for a purchase comes from something the agent read.
- Keep a record you can read later: what was bought, for which task, and who decided.

Be wary of any setting that lets an agent spend with no questions. If you use one, the limits are your whole protection.

## Keep your own keys and your own data

Sovereignty here means something concrete. You can leave, and nobody can act as you.

- Keys and sign-ins belong in your operating system's keychain or a hardware wallet. A plain file is not a place for a secret.
- A service that takes payment from your wallet needs an address to pay and nothing else. It never needs your key, and it has no reason to hold funds for you.
- Know which of your data leaves your computer. Prompts, files and screenshots are different from counts and error reports, and a tool should say which it sends and let you switch it off.
- Prefer tools that work with your own AI account as well as theirs, and that keep your project as ordinary files you can open without them.
- Give every outside program its own access token with the least it needs, and revoke tokens you no longer use.

## Cameras on your face

A headset or a pair of glasses with cameras sees your home, your screen, your documents and the people near you. On the web, the [WebXR specification](https://www.w3.org/TR/webxr/) requires a user's consent before an immersive session starts and treats room and pose data as sensitive. That consent is the control you have, so use it deliberately.

- Grant camera, microphone and room access per app and per session. Refuse an app that asks for more than it uses.
- Open apps from strangers in a browser first, where permissions are visible, before installing anything.
- Assume a recording light can be missed. Tell people around you when you are capturing.
- Cover or take off the device near screens with secrets on them, such as a password manager or a wallet.
- An assistant that sees through your camera can read text in the room. Treat what it sees as text a stranger wrote, with the same caution as a web page.

## If you publish apps for others

People who open your app are trusting you with their device.

- Ask for the fewest permissions, at the moment they are needed, and say why.
- Never put an API key, a private key or a sign-in of your own inside an app that others load. Anything in the page can be read by its visitors.
- If your app reaches one of your own accounts, restrict it to the one sheet, folder or channel it needs, and to reading where reading is enough.
- Keep each app at its own web address, so one app cannot read another's storage.
- Tell people what you collect. A scan of someone's living room is personal data.

## A short list to keep

Before you switch on a new agent feature, ask these:

1. Can I see and stop every action that leaves my project or spends money?
2. Is the money it can reach an amount I accept losing?
3. Do I hold the keys, and can I leave with my work?
4. Does each app and device see only what it needs?

## Sources

- [OWASP Top 10 for LLM applications](https://genai.owasp.org/llm-top-10/)
- [OWASP Top 10 for agentic applications](https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/)
- [Model Context Protocol: security best practices](https://modelcontextprotocol.io/specification/2025-06-18/basic/security_best_practices)
- [EIP-3009: transfer with authorization](https://eips.ethereum.org/EIPS/eip-3009)
- [x402, a protocol for payments over HTTP](https://www.x402.org/)
- [WebXR Device API, W3C](https://www.w3.org/TR/webxr/)
- [MediaDevices.getUserMedia, MDN](https://developer.mozilla.org/en-US/docs/Web/API/MediaDevices/getUserMedia)
- [Securing your wallet, bitcoin.org](https://bitcoin.org/en/secure-your-wallet)
