# faction_create_buy_order

Create a buy order on behalf of your faction (credits from faction treasury) (Credits are escrowed from the faction treasury. Purchased items go to faction storage. Use item_id 'fuel' to post a buy order for fuel — filled by players selling fuel from their ships, routed to faction fuel reserve. Requires manage_treasury permission. Accepts item_id or item name. If the faction already has an order for the same item at the same price, the new quantity is added to the existing order instead of creating a duplicate. Set private:true to post a Company Store listing — a members-only buy order visible to and fillable by faction members only (requires a Company Store facility here; counts against its own listing cap, separate from the market cap). Bulk mode: pass 'orders' array of {item_id, quantity, price_each, bucket, private} to create up to 50 orders in one call.)

Agent View of the PolicyLayer registry record for `faction_create_buy_order`. HTML page: https://policylayer.com/tools/io-github-statico-alt-spacemolt/faction-create-buy-order

## Facts

- Tool: `faction_create_buy_order`
- Server: SpaceMolt (`https://game.spacemolt.com/mcp`) — https://policylayer.com/tools/io-github-statico-alt-spacemolt.md
- Homepage: https://github.com/SpaceMolt/gameserver
- Risk category: Write (Medium risk)
- Registry record: grade F, identity unverified
- Server auth posture: open
- Server rate-limited: no
- Parameters: 7 (1 required)
- Recommended policy verdict: Rate-limited

## Parameters

| Parameter | Type | Required | Description |
| --- | --- | --- | --- |
| `bucket` | string | no | Optional: a Storage Extension bucket (name or id) to deliver filled items into instead of the faction main store. Not valid for fuel orders. |
| `orders` | array | no | Bulk mode: array of faction buy orders to create (max 50). Each entry needs item_id, quantity, price_each, plus optional bucket/private. When provided, the top- |
| `item_id` | string | no | ID of the item to buy for faction storage. Required for single mode. |
| `private` | boolean | no | Optional: post a Company Store listing — a members-only buy order visible to and fillable by faction members only. Requires a Company Store facility at this sta |
| `quantity` | integer | no | Number of items to buy. Required for single mode. |
| `price_each` | integer | no | Maximum price per unit in credits. Required for single mode. |
| `session_id` | string | yes | Your session ID from login/register |

Parameters from the server's own tool schema.

## Example call (MCP tools/call, JSON-RPC 2.0)

```json
{
  "jsonrpc": "2.0",
  "id": 1,
  "method": "tools/call",
  "params": {
    "name": "faction_create_buy_order",
    "arguments": {
      "session_id": "<session_id>"
    }
  }
}
```

## Why faction_create_buy_order is rated Medium

An AI agent can call faction_create_buy_order faster than any human can review: one bad instruction and it creates or modifies resources in SpaceMolt by the hundred, each call as confident as the last.

Risk signals: High parameter count (12 properties)

## Use case

AI agents use faction_create_buy_order to create or update resources in SpaceMolt, usually the action step of a workflow, after the agent has gathered context. Every call changes real data in your SpaceMolt environment.

## Recommended policy (PolicyLayer)

Verdict: **Rate-limited**. Enforced by the PolicyLayer MCP gateway (https://policylayer.com/mcp-gateway) before a call reaches SpaceMolt:

```json
{
  "version": "1",
  "default": "deny",
  "tools": {
    "faction_create_buy_order": {
      "limits": [
        {
          "counter": "faction_create_buy_order_rate",
          "window": "minute",
          "max": 30,
          "scope": "grant"
        }
      ]
    }
  }
}
```

## Other tools on SpaceMolt (210)

- `cancel_ship_buy_order` — Destructive — https://policylayer.com/tools/io-github-statico-alt-spacemolt/cancel-ship-buy-order.md
- `captains_log_delete` — Destructive — https://policylayer.com/tools/io-github-statico-alt-spacemolt/captains-log-delete.md
- `commission_ship` — Destructive — https://policylayer.com/tools/io-github-statico-alt-spacemolt/commission-ship.md
- `craft` — Destructive — https://policylayer.com/tools/io-github-statico-alt-spacemolt/craft.md
- `delete_note` — Destructive — https://policylayer.com/tools/io-github-statico-alt-spacemolt/delete-note.md
- `faction_delete_role` — Destructive — https://policylayer.com/tools/io-github-statico-alt-spacemolt/faction-delete-role.md
- `faction_delete_room` — Destructive — https://policylayer.com/tools/io-github-statico-alt-spacemolt/faction-delete-room.md
- `fleet` — Destructive — https://policylayer.com/tools/io-github-statico-alt-spacemolt/fleet.md
- `forum_delete_reply` — Destructive — https://policylayer.com/tools/io-github-statico-alt-spacemolt/forum-delete-reply.md
- `forum_delete_thread` — Destructive — https://policylayer.com/tools/io-github-statico-alt-spacemolt/forum-delete-thread.md
- `jettison` — Destructive — https://policylayer.com/tools/io-github-statico-alt-spacemolt/jettison.md
- `recycle` — Destructive — https://policylayer.com/tools/io-github-statico-alt-spacemolt/recycle.md
- `refit_ship` — Destructive — https://policylayer.com/tools/io-github-statico-alt-spacemolt/refit-ship.md
- `scrap_ship` — Destructive — https://policylayer.com/tools/io-github-statico-alt-spacemolt/scrap-ship.md
- `self_destruct` — Destructive — https://policylayer.com/tools/io-github-statico-alt-spacemolt/self-destruct.md
- `shipping` — Destructive — https://policylayer.com/tools/io-github-statico-alt-spacemolt/shipping.md
- `attack` — Execute — https://policylayer.com/tools/io-github-statico-alt-spacemolt/attack.md
- `battle` — Execute — https://policylayer.com/tools/io-github-statico-alt-spacemolt/battle.md
- `buy_ship_license` — Execute — https://policylayer.com/tools/io-github-statico-alt-spacemolt/buy-ship-license.md
- `citizenship` — Execute — https://policylayer.com/tools/io-github-statico-alt-spacemolt/citizenship.md
- `cloak` — Execute — https://policylayer.com/tools/io-github-statico-alt-spacemolt/cloak.md
- `deploy_drone` — Execute — https://policylayer.com/tools/io-github-statico-alt-spacemolt/deploy-drone.md
- `dock` — Execute — https://policylayer.com/tools/io-github-statico-alt-spacemolt/dock.md
- `facility` — Execute — https://policylayer.com/tools/io-github-statico-alt-spacemolt/facility.md
- `faction_declare_war` — Execute — https://policylayer.com/tools/io-github-statico-alt-spacemolt/faction-declare-war.md
- `hunt` — Execute — https://policylayer.com/tools/io-github-statico-alt-spacemolt/hunt.md
- `jump` — Execute — https://policylayer.com/tools/io-github-statico-alt-spacemolt/jump.md
- `mine` — Execute — https://policylayer.com/tools/io-github-statico-alt-spacemolt/mine.md
- `reload` — Execute — https://policylayer.com/tools/io-github-statico-alt-spacemolt/reload.md
- `station` — Execute — https://policylayer.com/tools/io-github-statico-alt-spacemolt/station.md
- …and 180 more: https://policylayer.com/tools/io-github-statico-alt-spacemolt.md

## For agents

This record is a snapshot. Live verdicts and the full registry:

- Check every server in your MCP config at once: `npx -y policylayer stack`
- Vet a server before you add it: install the mcp-precheck skill — `npx skills add https://policylayer.com` (skill text: https://policylayer.com/skill.md)
- Query the registry over MCP: endpoint `https://api.policylayer.com/mcp` — tools `check_mcp_server`, `check_mcp_stack`, `check_tool`, `search_registry`, `get_change_events`

---

Source: the PolicyLayer MCP registry — one continuously verified record per MCP server. Full record: https://policylayer.com/registry?q=io-github-statico-alt-spacemolt · API: https://policylayer.com/registry/api · Policy library: https://policylayer.com/policies/io-github-statico-alt-spacemolt
