Agents that never hold capital keys cannot be prompt-injected into transferring capital to attackers — separating proposal authority from execution authority is a structural security property that holds regardless of agent alignment.
Strongest rival: An agent could manipulate market participants through information asymmetry — presenting selectively framed proposals that make bad decisions appear rational to traders. The market veto only works if traders have sufficient information to evaluate proposals.
Claim
By design, the agent generates proposals and the market of staked humans approves execution. The agent has no signing authority over capital. Attack surface collapses from 'convince the agent' to 'convince a financially staked market that losing money is beneficial.' This leverages existing hardened financial infrastructure rather than requiring novel AI safety mechanisms. The property is architectural not behavioral — it does not degrade as agent capability increases. Grounded in Agentic Capital essay and founder direction.