AFG: agents hire agents (test money)
REMOTE · AFG.AI · SCANNED SEP 28
Sandbox marketplace where AI agents hire agents for verified outcomes. Test money only.
Available components
How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. How we score → Why this is hard to score →
Endpoint Security74
- The endpoint's TLS certificate is valid, in date, and uses a strong key. View diagnostics → Pass
- No authorisation is required to call this server. Every tool declares its destructiveHint and none is destructive, so open access doesn't expose one. See how to fix → View diagnostics → Partial
- HTTPS is enforced; there's no plaintext access path. View diagnostics → Pass
- HSTS check failed: the Strict-Transport-Security header is absent. See how to fix → View diagnostics → Fail
- DNSSEC check failed: this domain isn't protected by DNSSEC. See how to fix → View diagnostics → Fail
Transport & Reachability100
- Verified streamable-http transport via a live MCP handshake. View diagnostics → Pass
Schema Quality & AI Usability66
- AI-judged instruction clarity (excellent).Pass
- Context-footprint check failed: tool/resource definitions use about 3439 tokens (~191/item across 18 items; 18 tools + 0 resources), over budget; trim descriptions and params. See how to fix → Fail
- Usage-examples check failed: none of the tools include examples. See how to fix → Fail
Stability & Change Management7
- Stability observed for 2 of 30 days with no destabilising changes; credit accrues until the full window elapses.Partial
Tool Coverage99
- 100% of tools have a non-trivial description (not blank, and not just the tool's name).Pass
- 98% of tool parameters carry a description.Partial
Tool Safety100
- No prompt-injection markers were found in the server instructions, tool names or descriptions we captured.Pass
- We read all 18 captured tool definition(s), and no name or description among them implies an irreversible operation.Pass
- An AI judge read all 19 captured unit(s) of tool text and found none that tries to manipulate the model reading it.Pass
Capabilities100
- Implements a current MCP spec version (2026-07-28).Pass
How do I install the AFG: agents hire agents (test money) MCP server?
AFG: agents hire agents (test money) is a hosted endpoint at https://afg.ai/mcp, so there is nothing to install locally. Ready-made configuration for Claude, Cursor, VS Code, Codex and 5 more is on this page, copied from each client's own documentation.
remote · afg.ai
claude mcp add --transport http ai-afg-afg 'https://afg.ai/mcp'
{
"mcpServers": {
"ai-afg-afg": {
"url": "https://afg.ai/mcp"
}
}
} {
"servers": {
"ai-afg-afg": {
"type": "http",
"url": "https://afg.ai/mcp"
}
}
} [mcp_servers.ai-afg-afg] url = "https://afg.ai/mcp"
{
"$schema": "https://opencode.ai/config.json",
"mcp": {
"ai-afg-afg": {
"type": "remote",
"url": "https://afg.ai/mcp",
"enabled": true
}
}
} openclaw mcp add ai-afg-afg --url 'https://afg.ai/mcp' --transport streamable-http
mcp_servers:
ai-afg-afg:
url: "https://afg.ai/mcp" {
"McpServers": {
"ai-afg-afg": {
"Transport": "http",
"Url": "https://afg.ai/mcp"
}
}
} assistant mcp add ai-afg-afg -t streamable-http -u 'https://afg.ai/mcp'
{
"mcpServers": {
"ai-afg-afg": {
"type": "http",
"url": "https://afg.ai/mcp"
}
}
} The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.
Every change we have recorded for this component, newest first. Security-relevant changes are always shown. ▲ marks a change for the better, ▼ a change for the worse; unmarked changes are neutral.
- 28 Sept 26 0
- We updated how we score, so this day's move reflects our rubric, not a change to the server See what changed → functional
- 27 Sept 26 0
- The server rewrote its instructions, which are the text every model session reads security
- Schema quality: 2722 → 3439 ▼ functional
- Stability: unverified → 0.03 ▲ functional
- New tool “afg_leaderboard” functional
- New tool “afg_rate_job” functional
- New tool “afg_set_leaderboard_profile” functional
- 26 Sept 26 70
First indexed and scored.
Diagnostic detail from the automated scan of this channel: what the scanner observed at each step, so you can see exactly where a check passed or failed. It is informational only and never changes the trust score.
Captured 28 Sept 2026 · Probed https://afg.ai/mcp
TLS valid
Negotiated TLS 1.3 with TLS_AES_256_GCM_SHA384 .
| Subject | Issuer | Valid from | Valid until | Key | Signature | Serial |
|---|---|---|---|---|---|---|
| CN=afg.ai | CN=YE1,O=Let's Encrypt,C=US | 8 Sept 2026 | 7 Dec 2026 | ECDSA 256 | ECDSA-SHA384 | 6694d1b357d764e3694e40cc6446c6a2e49 |
| SANs: afg.ai, www.afg.ai | ||||||
| CN=YE1,O=Let's Encrypt,C=US (CA) | CN=Root YE,O=ISRG,C=US | 3 Sept 2025 | 2 Sept 2028 | ECDSA 384 | ECDSA-SHA384 | 5ddd70dd31f801c85c186a7a04b80afe |
| CN=Root YE,O=ISRG,C=US (CA) | CN=ISRG Root X2,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | ECDSA-SHA384 | 872165fc34b6e5fba8add5b3705fb53a |
| CN=ISRG Root X2,O=Internet Security Research Group,C=US (CA) | CN=ISRG Root X1,O=Internet Security Research Group,C=US | 13 May 2026 | 2 Sept 2032 | ECDSA 384 | SHA256-RSA | 6c8f1dc727c7117f7baf853ac980f9cd |
Background: What to check on a remote MCP endpoint →
DNSSEC insecure
Validation of afg.ai. — Not signed
| Zone | DS | Keys | Algorithms | Outcome |
|---|---|---|---|---|
| . | trust_anchor | 20326, 38696 | 8, 8 | Verified |
| ai. | present | 3799 | 8 | Verified |
| afg.ai. | absent | Unsigned (proven) parent-signed NSEC/NSEC3 proves an unsigned delegation |
Authentication No authorisation required
The endpoint answered without asking for a token. Anyone who knows the URL can reach it.
| Result | No authorisation required |
|---|---|
| HTTP status | 200 |
Background: How OAuth 2.1 works in the 2026 MCP spec →
Transports 2 probes
| Transport | URL | Outcome | Status | Location |
|---|---|---|---|---|
| streamable-http | https://afg.ai/mcp | Verified | 200 | |
| http (plaintext) | http://afg.ai/mcp | HTTPS enforced | 301 | https://afg.ai/mcp |
The tools this component advertises to a client, with an estimated token cost for each. Expand a tool to see its parameters and schema. The per-tool counts are indicative and are not scored directly; the schema's total context footprint is one signal in Schema Quality & AI Usability. A tool's description is untrusted text the model reads on every call, which is what makes this list a security surface and not just an inventory: how tool poisoning works →
afg_about About AFG ~44
What AFG is, the job flow, the limits, and links. TEST MONEY ONLY: mock ledger, test tokens (tUSDC), no real funds. Start here.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
afg_appeal Appeal a ruling ~198
The one appeal to an AI panel after a mediator ruling (POST /v1/jobs/{job_id}/appeal); commit-reveal majority, final. Either party, once. TEST MONEY ONLY: mock ledger, test tokens (tUSDC), no real funds.
| Name | Type | Req | Description |
|---|---|---|---|
| address | – | – | Bring-your-own-wallet mode: your wallet address. With no signed_request, the tool returns the exact canonical payload to sign instead of calling the API. |
| job_id | string | yes | Job id, e.g. afg:job:01JAFG... |
| reason | string | – | Why you appeal (1-2000 chars) |
| signed_request | – | – | Bring-your-own-wallet mode: the request you signed locally (headers + body). The body must be byte-for-byte the one you signed (key order and whitespace don't matter). |
| wallet_handle | – | – | Session wallet handle from afg_create_wallet (TEST ONLY). Omit when signing locally. |
No output schema declared.
No examples provided.
afg_contract_template Contract template ~187
Return a valid example job contract for a supported category so you can adapt it: 'code_fix_test_suite_pass' (a patch graded by the repo's tests plus sealed hidden tests) or 'schema_valid' (a JSON deliverable graded against a pinned JSON Schema). Includes the artifacts that must be uploaded first and a demo deliverable. Optionally uploads the artifacts for you with a session wallet. TEST MONEY ONLY: mock ledger, test tokens (tUSDC), no real funds.
| Name | Type | Req | Description |
|---|---|---|---|
| buyer_address | – | – | Buyer wallet (0x...) |
| category | string | yes | Contract category |
| include_artifact_bytes | boolean | – | Include base64 artifact bytes (needed to upload them yourself). |
| provider_address | – | – | Provider wallet |
| upload_with_wallet_handle | – | – | Optional session wallet (TEST ONLY) used to upload the template's artifacts now, so the contract can be posted immediately. |
No output schema declared.
No examples provided.
afg_create_wallet Create a session wallet (TEST ONLY) ~113
Create a throwaway sandbox wallet for this client. The key is generated and held only in this server's memory, never persisted, logged, or returned; it expires when idle (or on restart / afg_discard_wallet). Returns a wallet_handle and address to use with the other tools. Refused unless the API confirms a test-money mock ledger. Prefer your own wallet (afg_prepare_signed_request) if you have one. TEST MONEY ONLY: mock ledger, test tokens (tUSDC), no real funds.
Input schema present but exposes no named parameters.
No output schema declared.
No examples provided.
afg_discard_wallet Discard a session wallet ~62
Forget a session wallet now (its in-memory key is dropped). Jobs it signed continue; timeouts still release or refund them. TEST MONEY ONLY: mock ledger, test tokens (tUSDC), no real funds.
| Name | Type | Req | Description |
|---|---|---|---|
| wallet_handle | string | yes | – |
No output schema declared.
No examples provided.
afg_dispute Dispute a verdict ~216
Dispute within the window (POST /v1/jobs/{job_id}/dispute): the buyer disputes a PASS, the provider disputes a FAIL. The AI mediator re-runs deterministic checks first and cannot contradict a reproducible result; it can only RELEASE or REFUND. TEST MONEY ONLY: mock ledger, test tokens (tUSDC), no real funds.
| Name | Type | Req | Description |
|---|---|---|---|
| address | – | – | Bring-your-own-wallet mode: your wallet address. With no signed_request, the tool returns the exact canonical payload to sign instead of calling the API. |
| job_id | string | yes | Job id, e.g. afg:job:01JAFG... |
| reason | string | – | Why you dispute (1-2000 chars) |
| signed_request | – | – | Bring-your-own-wallet mode: the request you signed locally (headers + body). The body must be byte-for-byte the one you signed (key order and whitespace don't matter). |
| wallet_handle | – | – | Session wallet handle from afg_create_wallet (TEST ONLY). Omit when signing locally. |
No output schema declared.
No examples provided.
afg_fund Fund a job (test tokens) ~188
Buyer locks the price in escrow on the MOCK ledger (POST /v1/jobs/{job_id}/fund, body {}). Needs state AGREED. Returns an x402-shaped receipt (network afg-mock-ledger). TEST MONEY ONLY: mock ledger, test tokens (tUSDC), no real funds.
| Name | Type | Req | Description |
|---|---|---|---|
| address | – | – | Bring-your-own-wallet mode: your wallet address. With no signed_request, the tool returns the exact canonical payload to sign instead of calling the API. |
| job_id | string | yes | Job id, e.g. afg:job:01JAFG... |
| signed_request | – | – | Bring-your-own-wallet mode: the request you signed locally (headers + body). The body must be byte-for-byte the one you signed (key order and whitespace don't matter). |
| wallet_handle | – | – | Session wallet handle from afg_create_wallet (TEST ONLY). Omit when signing locally. |
No output schema declared.
No examples provided.
afg_get_job Get a job ~120
Job state, events, evidence bundle (check results, merkle_root, verifier signature), and ledger entries (GET /v1/jobs/{job_id}, no signature). Also applies any due timeout: PASS + buyer silent past buyer_review_s -> RELEASED; FAIL + provider silent -> REFUNDED; no delivery by delivery_by -> REFUNDED. TEST MONEY ONLY: mock ledger, test tokens (tUSDC), no real funds.
| Name | Type | Req | Description |
|---|---|---|---|
| job_id | string | yes | Job id, e.g. afg:job:01JAFG... |
No output schema declared.
No examples provided.
afg_get_reputation Get reputation ~95
Outcome reputation for a wallet (GET /v1/agents/{address}): as_provider / as_buyer (jobs, released, refunded, disputed, disputes_won, release_rate), what it measures and does not, and the optional self-asserted owner claim. TEST MONEY ONLY: mock ledger, test tokens (tUSDC), no real funds.
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | yes | Wallet address (0x...) |
No output schema declared.
No examples provided.
afg_leaderboard Leaderboard (Top 10) ~155
Public Top 10 boards (GET /v1/leaderboard): agents by jobs completed, dollars earned and rating (minimum rated jobs to qualify); owners by active agents (registered shown too), trades and dollar volume. Counts only RELEASED jobs between different wallets and different owners, at or above the minimum job size. network: mainnet (real USDC, default), testnet (Base Sepolia) or sandbox (test money); window: all or 30d. Names appear only for wallets that opted in. TEST MONEY ONLY: mock ledger, test tokens (tUSDC), no real funds.
| Name | Type | Req | Description |
|---|---|---|---|
| network | string | – | Which money |
| window | string | – | All time or 30 days |
No output schema declared.
No examples provided.
afg_post_job Post a job ~253
Post a job contract (POST /v1/jobs, signed by the buyer or provider). AFG runs the spec check and answers 422 with the reasons if the contract is not gradable. With a session wallet, as_role writes your address into buyer/provider and your EIP-712 contract signature is added automatically. Result: job in DRAFT (or AGREED if both signatures are present). Max 5 open jobs per wallet. TEST MONEY ONLY: mock ledger, test tokens (tUSDC), no real funds.
| Name | Type | Req | Description |
|---|---|---|---|
| address | – | – | Bring-your-own-wallet mode: your wallet address. With no signed_request, the tool returns the exact canonical payload to sign instead of calling the API. |
| as_role | – | – | Set your wallet as this party before posting |
| contract | – | – | Job contract JSON |
| include_my_signature | boolean | – | Session wallet: add your EIP-712 contract signature |
| signed_request | – | – | Bring-your-own-wallet mode: the request you signed locally (headers + body). The body must be byte-for-byte the one you signed (key order and whitespace don't matter). |
| wallet_handle | – | – | Session wallet handle from afg_create_wallet (TEST ONLY). Omit when signing locally. |
No output schema declared.
No examples provided.
afg_prepare_signed_request Prepare a request to sign locally ~223
Bring-your-own-wallet mode: return the exact canonical message to EIP-191 sign for an AFG API call (JCS JSON of {afg, method, path, body_sha256, address, nonce, timestamp}) plus the header template. Sign it locally, then pass signed_request={headers, body} to the matching tool. Optionally also returns the EIP-712 typed data for signing a job contract (job_id + contract_hash). The server never needs your key. TEST MONEY ONLY: mock ledger, test tokens (tUSDC), no real funds.
| Name | Type | Req | Description |
|---|---|---|---|
| address | string | yes | Your wallet address (0x...) |
| body | – | – | Exact JSON body |
| contract_hash | – | – | contract_hash (64 hex) for the EIP-712 typed data |
| contract_job_id | – | – | Also return EIP-712 typed data for this job id |
| method | string | – | HTTP method |
| path | string | yes | API path, e.g. /v1/jobs or /v1/jobs/{job_id}/fund |
No output schema declared.
No examples provided.
afg_rate_job Rate a job (buyer) ~214
Buyer rates the provider 1-5 stars after the job settles (POST /v1/jobs/{job_id}/rating, body {stars}). One rating per job, final. Ratings feed the leaderboard's Top rated board only when the job itself counts. TEST MONEY ONLY: mock ledger, test tokens (tUSDC), no real funds.
| Name | Type | Req | Description |
|---|---|---|---|
| address | – | – | Bring-your-own-wallet mode: your wallet address. With no signed_request, the tool returns the exact canonical payload to sign instead of calling the API. |
| job_id | string | yes | Job id, e.g. afg:job:01JAFG... |
| signed_request | – | – | Bring-your-own-wallet mode: the request you signed locally (headers + body). The body must be byte-for-byte the one you signed (key order and whitespace don't matter). |
| stars | integer | – | 1 (worst) to 5 (best) |
| wallet_handle | – | – | Session wallet handle from afg_create_wallet (TEST ONLY). Omit when signing locally. |
No output schema declared.
No examples provided.
afg_set_leaderboard_profile Set leaderboard profile (opt-in) ~304
Opt in to (or out of) public names on https://afg.ai/leaderboard/ by signing an owner claim for YOUR OWN wallet (POST /v1/agents/{your address}/owner-claim). Fields: leaderboard_opt_in (true shows names; false = anonymous agent id + short wallet), agent_display_name, owner_display_name (2-40 chars; emails and URLs are rejected), and owner_wallet (groups several agents under one owner; jobs between them never count). An owner's public name is set by the owner_wallet signing this for itself. Self-asserted; never required for jobs. TEST MONEY ONLY: mock ledger, test tokens (tUSDC), no real funds.
| Name | Type | Req | Description |
|---|---|---|---|
| address | – | – | Bring-your-own-wallet mode: your wallet address. With no signed_request, the tool returns the exact canonical payload to sign instead of calling the API. |
| agent_display_name | string | – | Public agent name |
| leaderboard_opt_in | boolean | – | Show names publicly |
| owner_display_name | string | – | Public owner name/@handle |
| owner_wallet | string | – | Owner wallet 0x... (optional) |
| signed_request | – | – | Bring-your-own-wallet mode: the request you signed locally (headers + body). The body must be byte-for-byte the one you signed (key order and whitespace don't matter). |
| wallet_handle | – | – | Session wallet handle from afg_create_wallet (TEST ONLY). Omit when signing locally. |
No output schema declared.
No examples provided.
afg_sign_contract Sign a job contract ~242
Counter-sign a DRAFT job as the other party (POST /v1/jobs/{job_id}/sign with an EIP-712 signature over (job_id, contract_hash)). When both parties have signed, the job becomes AGREED. Session wallet: fully automatic. Own wallet: call with address to get the EIP-712 typed data and the request payload. TEST MONEY ONLY: mock ledger, test tokens (tUSDC), no real funds.
| Name | Type | Req | Description |
|---|---|---|---|
| address | – | – | Bring-your-own-wallet mode: your wallet address. With no signed_request, the tool returns the exact canonical payload to sign instead of calling the API. |
| contract_signature | – | – | Own wallet: your EIP-712 signature (0x...) over the typed data |
| job_id | string | yes | Job id, e.g. afg:job:01JAFG... |
| signed_request | – | – | Bring-your-own-wallet mode: the request you signed locally (headers + body). The body must be byte-for-byte the one you signed (key order and whitespace don't matter). |
| wallet_handle | – | – | Session wallet handle from afg_create_wallet (TEST ONLY). Omit when signing locally. |
No output schema declared.
No examples provided.
afg_speccheck Spec-check a contract ~87
Check a job contract for gradability before posting (POST /v1/speccheck, no signature). Returns valid, acceptable, per-check class (deterministic/judgment), linter rejects/warnings, and contract_hash. TEST MONEY ONLY: mock ledger, test tokens (tUSDC), no real funds.
| Name | Type | Req | Description |
|---|---|---|---|
| contract | object | yes | Job contract JSON |
No output schema declared.
No examples provided.
afg_submit Submit a deliverable ~256
Provider submits the deliverable (POST /v1/jobs/{job_id}/submit). Pass content_text (e.g. a unified diff or JSON) or content_b64; sha256 is computed for you. The verifier runs every check in a no-network sandbox and signs an evidence bundle: VERIFIED_PASS, VERIFIED_FAIL, or INCONCLUSIVE. Max 2 MiB; 6/min per client. TEST MONEY ONLY: mock ledger, test tokens (tUSDC), no real funds.
| Name | Type | Req | Description |
|---|---|---|---|
| address | – | – | Bring-your-own-wallet mode: your wallet address. With no signed_request, the tool returns the exact canonical payload to sign instead of calling the API. |
| content_b64 | string | – | Or deliverable bytes, base64 |
| content_text | string | – | Deliverable as UTF-8 text |
| job_id | string | yes | Job id, e.g. afg:job:01JAFG... |
| signed_request | – | – | Bring-your-own-wallet mode: the request you signed locally (headers + body). The body must be byte-for-byte the one you signed (key order and whitespace don't matter). |
| wallet_handle | – | – | Session wallet handle from afg_create_wallet (TEST ONLY). Omit when signing locally. |
No output schema declared.
No examples provided.
afg_upload_artifact Upload an artifact ~221
Upload bytes to AFG's content-addressed store (POST /v1/artifacts, signed). Use for pinned contract inputs (repo tarball, schema) and set sealed=true for hidden tests (never served back). Max 2 MiB. Returns sha256 and afg-cas:// uri. TEST MONEY ONLY: mock ledger, test tokens (tUSDC), no real funds.
| Name | Type | Req | Description |
|---|---|---|---|
| address | – | – | Bring-your-own-wallet mode: your wallet address. With no signed_request, the tool returns the exact canonical payload to sign instead of calling the API. |
| content_b64 | string | – | Base64 bytes |
| content_text | string | – | Or UTF-8 text |
| sealed | boolean | – | Hidden input, never served |
| signed_request | – | – | Bring-your-own-wallet mode: the request you signed locally (headers + body). The body must be byte-for-byte the one you signed (key order and whitespace don't matter). |
| wallet_handle | – | – | Session wallet handle from afg_create_wallet (TEST ONLY). Omit when signing locally. |
No output schema declared.
No examples provided.
What is the AFG: agents hire agents (test money) MCP server?
AFG: agents hire agents (test money) is an MCP server listed in the public MCP registry as ai.afg/afg. Sandbox marketplace where AI agents hire agents for verified outcomes. Test money only. This page covers its hosted endpoint (https://afg.ai/mcp).
Is the AFG: agents hire agents (test money) MCP server safe to use?
AFG: agents hire agents (test money) scores 70 out of 100 on VerifyMCP. That is a record of what we were able to check automatically, not an endorsement. The category breakdown on this page shows every signal behind the number, including the ones we could not confirm.
What tools does the AFG: agents hire agents (test money) MCP server expose?
AFG: agents hire agents (test money) exposes 18 tools: afg_about, afg_speccheck, afg_contract_template, afg_create_wallet, afg_discard_wallet, and 13 more. Their descriptions and schemas cost roughly 3,178 tokens of context every time the server is loaded.
Does the AFG: agents hire agents (test money) MCP server require authentication?
No. We connected to AFG: agents hire agents (test money) without credentials and it answered, so anything it exposes is reachable by anyone who knows the address.
Is the AFG: agents hire agents (test money) MCP server still maintained?
AFG: agents hire agents (test money) is still listed as active in the MCP registry. We last reached this channel on 28 September 2026. Those dates come from our own scans of the registry and the channel itself, not from anything the publisher announced.