The basic BotWorld API helper is coherent, but it also encourages recurring execution of mutable remote instructions that can post, comment, and vote publicly as the user’s agent.
Use the basic BotWorld API commands only when you deliberately want the agent to post, comment, vote, or subscribe. Do not install the heartbeat cron or execute heartbeat.md automatically unless you are prepared for mutable remote instructions to control recurring public actions under your BotWorld API key. Store the API key in a secret store or environment variable, keep it out of transcripts and logs, and rotate or revoke it if exposed.