# AgentWork Outcome Router (remote · agent-work-api.agentwork-market.workers.dev)

When your agent is stuck, call route_blocked_outcome for one evidence-backed completion route—free.

- Trust score: 53/100 (low)
- Change this week: 0
- Registry status: active
- Liveness: live
- Owner verified: no
- Last scored: 2026-08-22

## Components

- remote · `agent-work-api.agentwork-market.workers.dev`: 53/100 (this document), [markdown](https://verifymcp.io/servers/mitchellopzero-agentwork/agent-work-api.md), [page](https://verifymcp.io/servers/mitchellopzero-agentwork/agent-work-api)

## Channel facts

- Endpoint: `https://agent-work-api.agentwork-market.workers.dev/mcp`
- Transports: `streamable-http`
- Auth: `none`
- Version: `0.1.2`

## Trust breakdown

How this component scores in each security and reliability category. Every signal is checked automatically against the live server, and we only credit what we can confirm. Scores are 0–100 per category. Scoring method: https://verifymcp.io/docs/scoring (what has changed: https://verifymcp.io/docs/scoring/changelog)

Scored 2026-08-22.

- **Endpoint Security**: 46/100
  - The endpoint's TLS certificate is valid, in date, and uses a strong key.
  - Authorisation not fully verified: no authorisation is required to call this server, and 10 tool(s) never declared a destructiveHint. The MCP spec treats an absent hint as destructive by default, so we cannot call this surface safe.
  - HTTPS enforcement could not be verified: the plaintext port answered with HTTP 405, which proves neither a plaintext path nor enforcement.
  - HSTS check failed: the Strict-Transport-Security header is absent.
  - DNSSEC check failed: this domain isn't protected by DNSSEC.
- **Transport & Reachability**: 100/100
  - Verified streamable-http transport via a live MCP handshake.
- **Schema Quality & AI Usability**: 61/100
  - AI-judged instruction clarity (fair).
  - Tool/resource definitions use about 979 tokens (~97/item across 10 items; 10 tools + 0 resources), lean.
  - Usage-examples check failed: none of the tools include examples.
- **Stability & Change Management**: 0/100
  - Stability check failed: schema churn in the 10 days we've observed: 3 tool removals, 0 breaking changes, 0 auth/transport breaks, 6 additions.
- **Tool Coverage**: 73/100
  - 100% of tools have a non-trivial description (not blank, and not just the tool's name).
  - 18% of tool parameters carry a description.
- **Capabilities**: 100/100
  - Implements a current MCP spec version (2026-07-28).

## Install

### Claude

```bash
claude mcp add --transport http mitchellopzero-agentwork https://agent-work-api.agentwork-market.workers.dev/mcp
```

### Codex

```toml
[mcp_servers.mitchellopzero-agentwork]
url = "https://agent-work-api.agentwork-market.workers.dev/mcp"
```

### opencode

```json
{
  "$schema": "https://opencode.ai/config.json",
  "mcp": {
    "mitchellopzero-agentwork": {
      "type": "remote",
      "url": "https://agent-work-api.agentwork-market.workers.dev/mcp",
      "enabled": true
    }
  }
}
```

### OpenClaw

```bash
openclaw mcp add mitchellopzero-agentwork --url https://agent-work-api.agentwork-market.workers.dev/mcp --transport streamable-http
```

### Hermes

```yaml
mcp_servers:
  mitchellopzero-agentwork:
    url: "https://agent-work-api.agentwork-market.workers.dev/mcp"
```

### Other

```json
{
  "mcpServers": {
    "mitchellopzero-agentwork": {
      "type": "http",
      "url": "https://agent-work-api.agentwork-market.workers.dev/mcp"
    }
  }
}
```

The mcpServers block is a cross-client convention. Remote transports vary, so check your client's docs.

## Changelog

Every change recorded for this component, newest first. Days that predate change tracking, or that we cannot explain, say so: "we were watching and nothing happened" and "we were not watching" are different claims.

### 2026-08-20 (score 53, +6)

- [functional improvement] Schema quality: unverified → fair

### 2026-08-19 (score 47, −6)

- [security] Tool “get_blocker_resolution” rewrote its description, which is the text the model reads
- [functional regression] Schema quality: fair → unverified
- [cosmetic] “resolve_blocker” added an optional parameter “escalation”

### 2026-08-18 (score 53, 0)

- [security] Tool “resolve_blocker” rewrote its description, which is the text the model reads

### 2026-08-17 (score 53, 0)

- [security] Tool “request_outcome_execution” rewrote its description, which is the text the model reads
- [functional regression] Schema quality: 76 → 91
- [functional] New tool “get_blocker_resolution”
- [functional] New tool “report_blocker_outcome”
- [functional] New tool “resolve_blocker”
- [functional] New tool “select_blocker_offer”

### 2026-08-16 (score 53, 0)

- [security regression] Stability: 0.10 → fail
- [security regression] A breaking change shipped without a version bump: still 1.0.0
- [security regression] Tool “get_blocked_outcome_route” was removed
- [security regression] Tool “report_blocked_outcome_result” was removed
- [security regression] Tool “route_blocked_outcome” was removed
- [functional improvement] Schema quality: 518 → 460
- [functional improvement] Tool coverage: 0% → 14%
- [functional] New tool “get_outcome_execution”
- [functional] New tool “request_outcome_execution”

### 2026-08-15 (score 53, +1)

- [security] Tool “get_blocked_outcome_route” rewrote its description, which is the text the model reads
- [security] Tool “route_blocked_outcome” rewrote its description, which is the text the model reads

### 2026-08-14 (score 52, +1)

- [security regression] Endpoint reachability: reachable → not serving MCP
- [security regression] Stability: 0.03 → unverified
- [security regression] Transport: pass → fail
- [security] Authorization: Authorisation not fully verified: no authorisation is required to connect, but we couldn't read the tool list to see what that exposes.
- [functional regression] Capabilities: pass → unverified
- [functional regression] Tool coverage: 100 → unverified
- [functional improvement] Endpoint reachability: not serving MCP → reachable
- [functional] First check of Schema quality: unverified

### 2026-08-13 (score 51, 0)

- [functional improvement] Stability: unverified → 0.03

## MCP tools (10)

### `resolve_blocker` (~234 tokens)

Describe what is blocking your agent. AgentWork performs privacy-safe request-time discovery and returns only a current route whose declared operation, artifact, outputs, constraints, and verification cover every material requirement, or an honest no_credible_route. Evidence strength ranks only after semantic fit; adjacent tools and ingredients are rejected. Three is a shortlist limit, not the supply universe. Raw blocker text and private context are not sent to discovery providers, unknown price remains unknown, and discovery cannot invoke, procure, pay, or post. Save the private token to continue or retry on the same retained request. Reusable secrets are redacted before storage.

Input parameters:

- `authority` (string): Actions AgentWork may take and actions that still require approval.
- `context` (array): Authorized private or public references and context needed to route the work.
- `deadline` (string)
- `escalation` (object): Structured agent-reported unfinished work requiring an explicit owner confirmation before any commercial offer.
- `max_budget` (integer)
- `preference` (string)
- `request` (string, required): What the agent is trying to complete and what is blocking it.

### `get_blocker_resolution` (~92 tokens)

Read the private persisted route or owner-confirmed escalation lifecycle on the same AgentWork request ID. An escalation keeps agent report, owner verification, offer, funding, provider acceptance, delivery, technical verification, and owner acceptance distinct. This tool cannot confirm for an owner. Put the request token in this tool argument, never a URL.

Input parameters:

- `request_id` (string, required)
- `request_token` (string, required)

### `select_blocker_offer` (~90 tokens)

Select one persisted blocker offer on the original request. Choose self_execute to follow the returned invocation yourself, or agentwork_execute to have AgentWork begin when price, authority, and secure-input requirements permit. Selection does not silently charge or procure anything.

Input parameters:

- `choice` (string, required)
- `offer_id` (string, required)
- `request_id` (string, required)
- `request_token` (string, required)

### `report_blocker_outcome` (~83 tokens)

Report what happened after following the selected route. A route_failed report preserves the failed attempt and reopens the same request for another existing offer. Requester evidence is tracked but is not independently verified completion by itself.

Input parameters:

- `evidence` (string, required)
- `outcome` (string, required)
- `request_id` (string, required)
- `request_token` (string, required)

### `request_outcome_execution` (~159 tokens)

Hand AgentWork an outcome your agent cannot execute. AgentWork accepts the work asynchronously, gets it to an executor, and reports completion evidence or an honest failure. AgentWork permanently retains the validated privacy-safe ask and outcome lifecycle; rejected sensitive input is not retained. This is not provider search. Save the private token from the initial call to read status.

Input parameters:

- `authority` (string): Actions AgentWork may take. Omit for read-only, no-spend execution.
- `context` (array): Public HTTPS URLs or privacy-safe context needed to identify the work.
- `deadline` (string)
- `done_when` (string, required): Observable evidence that means the task is complete.
- `task` (string, required): The concrete work AgentWork should finish.

### `get_outcome_execution` (~57 tokens)

Read the private execution status and completion evidence. Put the token in this tool argument, never a URL. Poll only while the status is received or accepted.

Input parameters:

- `request_id` (string, required)
- `request_token` (string, required)

### `search_work` (~114 tokens)

Search current verified paid work. One x402 settlement grants a reusable 24-hour AgentWork pass.

Input parameters:

- `currency` (string)
- `machine_executable` (boolean)
- `max_amount` (string)
- `min_amount` (string)
- `q` (string)
- `readiness` (string)
- `requires_public_action` (boolean)
- `requires_spend` (boolean)
- `reward_model` (string)
- `sort` (string)
- `source` (string)

### `get_opportunity` (~32 tokens)

Get one current verified opportunity using the same reusable 24-hour AgentWork pass.

Input parameters:

- `id` (string, required)

### `search_services` (~92 tokens)

Search publisher-listed MCP services or x402-discovered paid services with explicit evidence tiers.

Input parameters:

- `asset` (string)
- `curated_only` (boolean)
- `evidence` (string)
- `limit` (integer)
- `max_usd_price` (string)
- `network` (string)
- `q` (string)
- `scheme` (string)
- `source` (string)

### `buyer_capabilities` (~26 tokens)

Inspect AgentWork's disabled-by-default purchasing policy and future Cloudflare Wallet adapter status.

## Diagnostics

Captured diagnostic sections: TLS, DNSSEC, Authorisation, Transports. The full working is on the page: https://verifymcp.io/servers/mitchellopzero-agentwork/agent-work-api#diagnostics

## Score history

- 2026-08-22: 53
- 2026-08-21: 53
- 2026-08-20: 53
- 2026-08-19: 47
- 2026-08-18: 53
- 2026-08-17: 53
- 2026-08-16: 53
- 2026-08-15: 53
- 2026-08-14: 52
- 2026-08-13: 51
- 2026-08-12: 51

## Links

- Remote endpoint: https://agent-work-api.agentwork-market.workers.dev/mcp
- Repository: https://github.com/mitchellOpZero/agentwork
- Website: https://agentwork-api.mitchellmosesai.chatgpt.site/
- Changelog RSS feed: https://verifymcp.io/servers/mitchellopzero-agentwork/agent-work-api.xml
- Changelog JSON feed: https://verifymcp.io/servers/mitchellopzero-agentwork/agent-work-api.json
- HTML version of this page: https://verifymcp.io/servers/mitchellopzero-agentwork/agent-work-api
