# Boundary & Risk Card

Project: OpenBB-finance/OpenBB

## Doramagic Trial Decision

Current decision: it can enter pre-publication recommendation checks. First use should still start with least privilege, a temporary directory, and reversible configuration.

## What The User Can Do Now

- Read the Human Manual first to understand the project purpose and main workflows.
- Use Prompt Preview for pre-install exploration; it validates interaction shape, not real execution.
- Run official Quick Start commands only inside an isolated environment, not a primary setup.

## Do Not Do Yet

- Do not treat Prompt Preview as a real project execution result.
- Do not treat metadata-only validation as sandbox installation validation.
- Do not describe unverified capabilities as supported, working, or safe to install.
- Do not provide production data, private files, real secrets, or primary host configuration on first trial.

## Pre-Install Checklist

- Host AI match: local_cli
- Official installation entry status: official entry point found
- Isolated temporary directory, temporary host, or container validation: required
- Configuration rollback path: required
- API keys, network access, file access, or host configuration changes: treat as high risk until confirmed
- Installation command, actual output, and failure logs: must be recorded

## Current Blockers

- No blockers.

## Project-Specific Pitfalls

- 来源证据：[FR] Add Bank of Canada Valet API as a new provider extension (high): 可能影响授权、密钥配置或安全边界。 Suggested check: 来源问题仍为 open，Pack Agent 需要复核是否仍影响当前版本。
- 来源证据：[FR] Add Real-time Cryptocurrency Data Provider Integration (high): 可能影响授权、密钥配置或安全边界。 Suggested check: 来源问题仍为 open，Pack Agent 需要复核是否仍影响当前版本。
- 来源证据：[FR] Signed audit receipts for MCP server tool calls (regulatory compliance) (high): 可能影响授权、密钥配置或安全边界。 Suggested check: 来源问题仍为 open，Pack Agent 需要复核是否仍影响当前版本。
- 涉及密钥、隐私或敏感领域 (high): 金融、交易、隐私和密钥场景必须比普通工具更保守。 Suggested check: 补敏感数据流、密钥存储和权限边界审查。
- 失败模式：installation: OpenBB Platform v4.5.0 (medium): Upgrade or migration may change expected behavior: OpenBB Platform v4.5.0 Suggested check: Before packaging this project, run the relevant install/config/quickstart check for: OpenBB Platform v4.5.0. Context: Observed when using python

## Risk And Permission Notes

- no_demo: medium

## Evidence Gaps

- No structured evidence gaps are currently visible.
