No consent, no start
Confirmer name and YYYY-MM-DD consent date are required. Future dates are rejected; session entry re-asserts ValidConsent. CLI requires --consent-by / --consent-date.
Safety
This tool runs against real sites. We enforce controls in code—not only in prompts.
Confirmer name and YYYY-MM-DD consent date are required. Future dates are rejected; session entry re-asserts ValidConsent. CLI requires --consent-by / --consent-date.
Order/payment confirm is refused and ends as pre-checkout reached. Early Buy now is also refused (no checkout credit). Enter/Space too. Unlabeled controls fail closed and are skipped.
Max 40 actions and $2. Budget is preflighted before model turns; overages stop as “action limit” or “cost limit”.
Visible vendor widgets stop the run immediately. Bare data-sitekey alone is not treated as CAPTCHA. No bypass.
Accesses as AgentQA-Bot/1.0 (+contact URL). Never impersonates a normal browser.
Public https hosts only. localhost and private IPs are rejected.
Enforced in code—not policy text alone.