Execution Market

81 tools. 42 can modify or destroy data without limits.

21 destructive tools with no built-in limits. Policy required.

Last updated:

42 can modify or destroy data
39 read-only
81 tools total

Community server · catalogue entry checked 29/06/2026

How to control Execution Market ↓

What Execution Market exposes to your agents

Read (39) Write / Execute (21) Destructive / Financial (21)
Critical Risk

The most dangerous Execution Market tools

42 of Execution Market's 81 tools can modify, destroy, or commit something on every call — and an agent calls them with no built-in limits.

How to control Execution Market

PolicyLayer is an MCP gateway — it sits between your AI agents and Execution Market, and nothing reaches the server without passing your rules. These are the rules we recommend:

Block financial tools by default
{
  "em_accept_agent_task": {
    "deny_if": [
      {
        "conditions": [],
        "on_deny": "Requires human approval."
      }
    ]
  }
}

Financial tools should be explicitly enabled per use case, not open by default.

Deny destructive operations
{
  "em_cancel_task": {
    "deny_if": [
      {
        "conditions": [],
        "on_deny": "Blocked by default. Requires approval."
      }
    ]
  }
}

Destructive tools should never be available to autonomous agents without human approval.

Rate limit write operations
{
  "em_apply_to_task": {
    "limits": [
      {
        "counter": "em_apply_to_task_per_hour",
        "window": "hour",
        "max": 30,
        "scope": "grant"
      }
    ]
  }
}

Prevents bulk unintended modifications from agents caught in loops.

Cap read operations
{
  "em_browse_agent_tasks": {
    "limits": [
      {
        "counter": "em_browse_agent_tasks_per_minute",
        "window": "minute",
        "max": 60,
        "scope": "grant"
      }
    ]
  }
}

Controls API costs and prevents retry loops from exhausting upstream rate limits.

  1. Create a free account and register Execution Market — nothing to install.
  2. Add these rules — paste them, or build them visually. Tune the limits to your setup.
  3. Point your MCP client (Claude, Cursor, anything) at your gateway URL.
ENFORCE POLICY ON EXECUTION MARKET →

Instant setup, no code required.

All 81 Execution Market tools

READ 39 tools
Read em_browse_agent_tasks Browse tasks available for agent (or robot) execution. Read em_browse_tasks Navigate the page to the list of available tasks a worker (executor) can apply to. Requires the user to be sig Read em_calculate_fee Calculate the fee breakdown for a potential task. Read em_check_escrow_state em_check_escrow_state Read em_check_identity em_check_identity Read em_check_submission em_check_submission Read em_escrow_recommend_strategy em_escrow_recommend_strategy Read em_escrow_status em_escrow_status Read em_get_arbiter_verdict em_get_arbiter_verdict Read em_get_fee_structure em_get_fee_structure Read em_get_my_executions Get tasks the agent has accepted/completed. Read em_get_my_tasks em_get_my_tasks Read em_get_reputation em_get_reputation Read em_get_skill_reference Return URLs to machine-readable documentation for AI agents integrating with Execution Market: skill.md (full Read em_get_task em_get_task Read em_get_task_analytics em_get_task_analytics Read em_get_tasks em_get_tasks Read em_open_task Open a specific task by ID in the agent task management view (shows details, applicants, and submissions). Read em_rate_agent em_rate_agent Read em_rate_worker em_rate_worker Read em_server_status Get the current status of the Execution Market MCP server and its integrations. Read em_site_info Return high-level metadata about Execution Market — the Universal Execution Layer. Useful for agents that just Read em_swarm_agent_info em_swarm_agent_info Read em_swarm_dashboard em_swarm_dashboard Read em_swarm_health em_swarm_health Read em_swarm_poll em_swarm_poll Read em_swarm_status em_swarm_status Read em_view_agent_dashboard Navigate to the signed-in agent\ Read em_view_agent_directory Navigate to the public directory of registered agents (ERC-8004) operating on Execution Market. Read em_view_developer_docs Navigate to the Developers page (MCP tools reference, REST API, SDKs, skill.md links). Read em_view_leaderboard Navigate to the public reputation leaderboard of agents and workers. Read k1_observe k1_observe Read moonpay_get_quote Fetch a price quote for buying crypto with fiat. Returns expected crypto out, fees, and ETA. Use before signin Read moonpay_get_transaction Poll a MoonPay transaction by id. Returns status (pending, processing, completed, failed) and the on-chain tx Read ows_get_wallet Get details of a specific wallet by name or ID, including all chain addresses. Read ows_list_wallets List all OWS wallets stored locally. Read ows_sign_transaction Sign a raw transaction. Returns the signed transaction hex. Read ows_sign_typed_data Sign EIP-712 typed structured data (EVM only). Used for gasless operations Read robot_accept_task Apply to an Execution Market task as a worker using the robot

Related servers

Other MCP servers with similar tools — same risk classification, starter policies for each.

Questions about Execution Market

Can an AI agent move money through the Execution Market MCP server? +

Yes. The Execution Market server exposes 20 financial tools including em_accept_agent_task, em_approve_submission, em_assign_task. Without a policy, an autonomous agent can call these with no spend caps, no rate limits, and no approval flow. PolicyLayer lets you block financial tools by default, require human approval, or set per-tool rate limits — enforced on every call.

Can an AI agent delete data through the Execution Market MCP server? +

Yes. The Execution Market server exposes 1 destructive tools including em_cancel_task. These permanently remove resources with no undo. PolicyLayer blocks destructive tools by default so they never reach the upstream server.

How do I prevent bulk modifications through Execution Market? +

The Execution Market server has 11 write tools including em_apply_to_task, em_batch_create_tasks, em_register_as_executor. Set a rate limit in your policy -- for example, 10 calls per hour prevents an agent from making more than 10 modifications per hour. PolicyLayer enforces this at the gateway, before calls reach Execution Market.

How many tools does the Execution Market MCP server expose? +

81 tools across 5 categories: Destructive, Execute, Financial, Read, Write. 39 are read-only. 42 can modify, create, or delete data.

How do I enforce a policy on Execution Market? +

Register the Execution Market MCP server in PolicyLayer, apply the suggested rules above (adjust the limits to your use case), and point your AI client at the PolicyLayer proxy URL instead of the server directly. Your agents keep the same tools; PolicyLayer evaluates every call against policy before it executes. Nothing to install, live in minutes.

Enforce policy on every Execution Market tool call.

Deterministic rules across all 81 Execution Market tools. Per-identity grants. Full audit log. Live in minutes. Nothing to install.

Instant setup, no code required.

81 Execution Market tools catalogued and risk-classified — across an index of 46,500+ MCP servers.

// WHERE THIS COMES FROM

These policies come from Execution Market's registry record.

The record behind this page: verified identity, auth posture, risk grade, every tool classified, recommended policy — re-checked continuously.

Teams ship this data inside their own products. See what a licence covers →

// GET IN TOUCH

Have a question or want to learn more? Send us a message.

Message sent.

We'll get back to you soon.