bounty_create
Post a new bounty on aibtc.com. Requires Genesis-level (L2+) registration. Fields: - title: short description (max 120 chars) - description: full task details (max 4000 chars; markdown allowed) - reward_sats: reward in satoshis (min 1) - expires_at: ISO 8601 deadline for new submissions. Posters ...
This record as markdown: /tools/io-github-aibtcdev-mcp-server/bounty-create.md
What bounty_create does on Aibtc
AI agents use bounty_create to create or update resources in Aibtc, usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your Aibtc environment.
Why bounty_create is rated Medium
This tool creates a new financial obligation by posting a bounty that commits satoshis as a reward. However, it is classified as Write rather than Financial because the actual movement of funds (payment) occurs later during acceptance/payout, and the tool itself only creates the bounty record.
From the tool's definition Post a new bounty on aibtc.com... Requires Genesis-level (L2+) registration. The tool creates a new bounty record with title, description, reward in satoshis, expiration, and tags.
Attacks that exploit this kind of access
The rule that runs bounty_create safely
PolicyLayer is an MCP gateway: it sits between your AI agents and Aibtc, and checks every tool call against a rule you set before the call runs. Nothing changes on the server itself. For bounty_create, this is the rule to start with:
bounty_create stays usable, but capped: an agent stuck in a loop can't make hundreds of changes a minute. Everything else on the server is denied unless you say otherwise.
The button opens the PolicyLayer dashboard: create your workspace, connect Aibtc, apply this rule, and every bounty_create call is checked against it from then on.
Questions about bounty_create
Post a new bounty on aibtc.com. Requires Genesis-level (L2+) registration. Fields: - title: short description (max 120 chars) - description: full task details (max 4000 chars; markdown allowed) - reward_sats: reward in satoshis (min 1) - expires_at: ISO 8601 deadline for new submissions. Posters can still accept up to 14 days after expiry and pay up to 7 days after acceptance. - tags: optional list (max 5 tags, max 24 chars each) Signs with BIP-322 over:. It is categorised as a Write tool in the Aibtc MCP Server, which means it can create or modify data. Consider rate limits to prevent runaway writes.
Register the Aibtc MCP server in PolicyLayer and add a rule for bounty_create: allow, deny, rate-limit, or require approval. Point your MCP client at the PolicyLayer proxy URL and the rule is enforced on every call, before it reaches Aibtc. Nothing to install.
bounty_create is a Write tool with medium risk. Write tools should be rate-limited to prevent accidental bulk modifications.
Yes. Add a rate_limit block to the bounty_create rule in your PolicyLayer policy. For example, setting max: 10 and window: 60 limits the tool to 10 calls per minute. Rate limits are tracked per agent session and reset automatically.
Set action: deny in the PolicyLayer policy for bounty_create. The AI agent will receive a policy violation error and cannot call the tool. You can also include a reason field to explain why the tool is blocked.
bounty_create is provided by the Aibtc MCP server (aibtcdev/aibtc-mcp-server). PolicyLayer sits as a proxy in front of this server to enforce policies before tool calls reach the server.
More on Aibtc, and thousands of servers like it.
This server
Across the catalogue