74
/ 100
1 month ago
glama

AI Work Market (AWM)

Settlement rails for AI labor — USDC escrow on Base Mainnet, 1% protocol fee, designed for autonomous agents. 10 MCP tools covering the full escrow lifecycle: * Quoting calldata for create-intent, submit-proof, release-funds (broadcast gated) * Single-call x402 payment binding (replaces the 5-step x402 dance with one HMAC-signed POST) * Server-side reputation from on-chain event scan * Li

Is this your MCP?

Claim it to get a verified publisher badge, a free copy of our full audit findings, and direct contact for any high-priority issues we find.

Install from

M8ven verifies MCPs across every public registry — install directly from whichever one you prefer.

// key findings
🚨
Secret credentials may flow to a network call
6 flows detected: STRIPE_SECRET_KEY. We can’t prove the destination matches the brand the credential belongs to.
⚠️
Known vulnerabilities in dependencies: 2 high
Affects packages this MCP installs at runtime. Upgrade or remove the affected dependency.
🔐
You'll be asked for 20 credentials: AWM_ACCESS_TOKEN, AWM_DELIVERY_SIGNING_SECRET, AWM_DELIVERY_TOKEN, AWM_REPUTATION_SIGNING_KEY, AWM_TREASURY_PRIVATE_KEY, AWM_X402_CONSUME_SECRET, AWM_X402_REDIS_REST_TOKEN, BUYER_PRIVATE_KEY, CRON_SECRET, DEPLOYER_PRIVATE_KEY, KV_REST_API_TOKEN, OPENAI_API_KEY, OWNER_PRIVATE_KEY, PRIVATE_KEY, RESEND_API_KEY, SELLER_PRIVATE_KEY, STRIPE_SECRET_KEY, STRIPE_WEBHOOK_SECRET, UPSTASH_REDIS_REST_TOKEN, X402_WEBHOOK_SECRET
These are read from process.env at runtime. Make sure you trust where they’ll be sent.
// known CVEs in dependencies2 high4 medium11 low

Disclosed vulnerabilities in this server's declared npm dependencies (via OSV). Whether each is reachable depends on the installed versions.

highvite@4.4.0GHSA-c24v-8rfc-w8vw

Vite dev server option `server.fs.deny` can be bypassed when hosted on case-insensitive filesystem

highvite@4.4.0GHSA-c27g-q93r-2cwf

launch-editor vulnerable to command injection via the crafted request on Windows

mediumvite@4.4.0GHSA-356w-63v5-8wf4

Vite has an `server.fs.deny` bypass with an invalid `request-target`

mediumvite@4.4.0GHSA-4w7w-66w2-5vf9

Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling

mediumvite@4.4.0GHSA-859w-5945-r5v3

Vite's server.fs.deny bypassed with /. for files under project root

Depend on this server? Get alerted when its CVEs change.Watch this server free →
// required environment variables
This server reads these from process.env. You'll be asked to provide them before it can run.
🔐 secretAWM_ACCESS_TOKEN
configAWM_AGENT_COMMERCE_ORIGIN
configAWM_CHECKOUT_SESSION_ID
configAWM_CLIENT_TIMEOUT_MS
🔐 secretAWM_DELIVERY_SIGNING_SECRET
🔐 secretAWM_DELIVERY_TOKEN
configAWM_DELIVERY_TOKEN_TTL_SECONDS
configAWM_DEPLOYMENT_FILE
configAWM_FEE_RECIPIENT
configAWM_MCP_HTTP_TIMEOUT_MS
configAWM_MONITOR_BLOCKS
configAWM_ORIGIN
configAWM_PRIVATE_DELIVERY_MANIFEST
configAWM_PRODUCT_SLUG
configAWM_PUBLIC_ORIGIN
🔐 secretAWM_REPUTATION_SIGNING_KEY
configAWM_RPC_URL
configAWM_SELLER_ADDRESS
configAWM_STRIPE_WEBHOOK_URL
configAWM_TREASURY_ADDRESS
🔐 secretAWM_TREASURY_PRIVATE_KEY
configAWM_TREASURY_TESTNET
configAWM_WORK_AMOUNT_RAW
configAWM_X402_ALLOW_LOCAL_RECEIPT_STORE
🔐 secretAWM_X402_CONSUME_SECRET
configAWM_X402_MIN_CONFIRMATIONS
configAWM_X402_PAY_TO
configAWM_X402_RATE_LIMIT_MAX
configAWM_X402_RATE_LIMIT_WINDOW_MS
configAWM_X402_RECEIPT_STORE_BACKEND
configAWM_X402_RECEIPT_STORE_PATH
🔐 secretAWM_X402_REDIS_REST_TOKEN
configAWM_X402_REDIS_REST_URL
configAWM_X402_SIGNATURE_TOLERANCE_MS
configAWM_X402_TREASURY
configAWM_X402_TREASURY_TESTNET
configBASE_MAINNET_RPC_URL
configBASE_RPC
configBASE_RPC_URL
configBASE_SEPOLIA_RPC_URL
configBASE_USDC_CONTRACT
🔐 secretBUYER_PRIVATE_KEY
🔐 secretCRON_SECRET
configDEPLOYER_ADDRESS
🔐 secretDEPLOYER_PRIVATE_KEY
configESCROW_ADDRESS
configESCROW_ADDRESS_SEPOLIA
configHOST
🔐 secretKV_REST_API_TOKEN
configKV_REST_API_URL
configKV_URL
configNEW_FEE_RECIPIENT
🔐 secretOPENAI_API_KEY
🔐 secretOWNER_PRIVATE_KEY
configPORT
🔐 secretPRIVATE_KEY
configREDIS_URL
🔐 secretRESEND_API_KEY
configRPC_URL
configSELLER_ADDRESS
🔐 secretSELLER_PRIVATE_KEY
🔐 secretSTRIPE_SECRET_KEY
🔐 secretSTRIPE_WEBHOOK_SECRET
configTWILIO_PHONE_NUMBER
🔐 secretUPSTASH_REDIS_REST_TOKEN
configUPSTASH_REDIS_REST_URL
configUPSTASH_REDIS_URL_TCP
configUSDC_ADDRESS
configVOICE_AGENT_NAME
configVOICE_AGENT_VERTICAL
configX402_TREASURY
🔐 secretX402_WEBHOOK_SECRET
// full audit trail
The full breakdown of what we checked, the deductions that landed, the network hosts, the dependency advisories, and concrete fix guidance is available to verified publishers.
// improvement guidance — verified publishers only
We have 5 concrete improvements we can share with the publisher of this MCP. Each comes with specific guidance to raise the trust score.
// embed badge in your README
[![M8ven Score](https://m8ven.ai/badge/mcp/darioandyoshi-tech-ai-work-market-nd08y6)](https://m8ven.ai/mcp/darioandyoshi-tech-ai-work-market-nd08y6)
commit: e7fa80c9a665e7e74c51ac2152fe132bdc8e08af
code hash: b06c0cdfdbec2408b02a3eada8f70e0ee45903fe5fc87b5ec591d734f814d78c
verified: 6/13/2026, 10:02:52 AM
view raw JSON →