# create_store

List a GitHub repo for sale: URL, price, payout wallet(s); USDC on Base (0x…) and/or Solana (base58); both offers the buyer the choice. Private repos need a fine-grained PAT (Contents read-only, that one repo), unless the account has the GitHub App installed on the repo, in which case no key is needed at all. The listing is live at page immediately.

Agent View of the PolicyLayer registry record for `create_store`. HTML page: https://policylayer.com/tools/com-gitbuyer-mcp/create-store

## Facts

- Tool: `create_store`
- Server: Mcp (`https://gitbuyer.com/mcp`) — https://policylayer.com/tools/com-gitbuyer-mcp.md
- Homepage: https://github.com/bitfent/gitbuyer
- Risk category: Write (Medium risk)
- Registry record: grade F, identity unverified
- Server auth posture: open
- Server rate-limited: no
- Parameters: 6 (1 required)
- Recommended policy verdict: Rate-limited

## Parameters

| Parameter | Type | Required | Description |
| --- | --- | --- | --- |
| `price_usd` | string | no | e.g. "25.00"; defaults to 20.00 |
| `github_pat` | string | no | fine-grained PAT for private repos |
| `github_url` | string | yes |  |
| `wallet_base` | string | no | USDC payout wallet on Base (0x…) |
| `preview_paths` | array | no | globs buyers may read free before paying |
| `wallet_solana` | string | no | USDC payout wallet on Solana |

Parameters from the server's own tool schema.

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "create_store",
    "arguments": {
      "github_url": "<github_url>"
    }
  }
}
```

## Why create_store is rated Medium

An AI agent can call create_store faster than any human can review: one bad instruction and it creates or modifies resources in Mcp by the hundred, each call as confident as the last.

## Use case

AI agents use create_store to create or update resources in Mcp, usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your Mcp environment.

## Recommended policy (PolicyLayer)

Verdict: **Rate-limited**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches Mcp:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "create_store": {
      "limits": [
        {
          "counter": "create_store_rate",
          "window": "minute",
          "max": 30,
          "scope": "grant"
        }
      ]
    }
  }
}
```

## Other tools on Mcp (15)

- `delete_store` — Destructive — https://policylayer.com/tools/com-gitbuyer-mcp/delete-store.md
- `find_base` — Read — https://policylayer.com/tools/com-gitbuyer-mcp/find-base.md
- `get_github` — Read — https://policylayer.com/tools/com-gitbuyer-mcp/get-github.md
- `get_repo` — Read — https://policylayer.com/tools/com-gitbuyer-mcp/get-repo.md
- `get_sales` — Read — https://policylayer.com/tools/com-gitbuyer-mcp/get-sales.md
- `get_stats` — Read — https://policylayer.com/tools/com-gitbuyer-mcp/get-stats.md
- `get_store` — Read — https://policylayer.com/tools/com-gitbuyer-mcp/get-store.md
- `get_traffic` — Read — https://policylayer.com/tools/com-gitbuyer-mcp/get-traffic.md
- `list_stores` — Read — https://policylayer.com/tools/com-gitbuyer-mcp/list-stores.md
- `search_repos` — Read — https://policylayer.com/tools/com-gitbuyer-mcp/search-repos.md
- `whoami` — Read — https://policylayer.com/tools/com-gitbuyer-mcp/whoami.md
- `create_payout_wallet` — Write — https://policylayer.com/tools/com-gitbuyer-mcp/create-payout-wallet.md
- `seller_setup` — Write — https://policylayer.com/tools/com-gitbuyer-mcp/seller-setup.md
- `set_payout_wallets` — Write — https://policylayer.com/tools/com-gitbuyer-mcp/set-payout-wallets.md
- `update_store` — Write — https://policylayer.com/tools/com-gitbuyer-mcp/update-store.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=com-gitbuyer-mcp · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/com-gitbuyer-mcp
