Alice leashes her assistant: ≤ $400, travel / rideshare only. The limits are signed constraints enforced offline at each merchant — a prompt injection physically can’t overspend. Then she revokes, and even the token the agent already holds dies at the merchant, because each merchant polls Legant’s signed /.well-known/revoked feed. Faithful replay of go run ./examples/leash.
The cap is a signed constraint, not a prompt rule — there’s no instruction to override.