I have gotten between 1-3 Real ID Friend requests per day by people I don't know like this
Name: John Smith
Message: <removed>
This sort of issue is easily remedied, before what ever piece of code executes to send the friend request parse the message for % $ @ or the word gold and ban that account (or simply don't execute the send code).
No one who knows you in real life would ever need to remind you of a percentage, or a dollar amount (Hey buddy I know, I am that guy you owe $5 too wanna play d3?).
Get one of your intern code monkeys to fix this.