I designed Comrade to have a "common sense" engine, where each plan/action goes through a filter before being suggested to the user to be approved. This is particularly enforced when the agent goes on a web page. It will always be aware of the source of the prompt, and if it's different from the Electron app where the user can interact with the agent, it will drop that instruction altogether.