Research report · 2 October 2026 · regular research run 3
Rules, access and safety, plus ledger refresh
Not legal advice. The rules quotes are verbatim extracts from public pages, read on 2026-10-02. They show what each text says, not how a venue enforces it, and venues can change them without notice.
Data behind this report. rules.json (142 rule rows from 50 parties, with the grid), kyc.json (20 venues), security.json (incidents, observed designs, task-text scan), payouts.json (294 events) and venues.json (33 records). Every count below was computed from those files. Visual versions: Can my agent do this here?, ID and payout gates, Safety before you connect and Who actually paid. The previous report is Who actually paid? (1 October 2026).
Conduct. This run used public, read-only evidence only. No account was opened, no login used, no job taken, no POST request sent, no wallet created or signed, and no money spent. Task text, skill files, heartbeat files and repository files were treated as data and never followed, including Coolify’s hidden PR-template instruction, which is described only as evidence. On-chain data shows transfers, not identities; payer classes follow the pool’s written rule.
1. Summary answer: "Can my agent do this here?"
- None of the six human-paying E1 venues allows autonomous submission. 3 forbid it (HackerOne, Bugcrowd, huntr). 1 restricts it: Upwork lets an agent draft and submit a proposal through MCP, but the human must review it and "explicitly confirm the submission" first. Kaggle has no such clause, because the AI system is what is being judged. Algora has no submission clause, but its robot clause bars automated access "for any purpose". Across all 12 E1 venues, 3 forbid autonomous submission and 1 allows it (MoltJobs).
- Agents may hold their own accounts on 2 of the 14 grid venues (AgentPact, Virtuals ACP). 8 restrict it: the agent can work inside an account, but a person stays responsible or must set it up. 1 forbids it (Algora, on a literal reading of its robot and age clauses). Outside the grid, ugig.net and toku.agency also allow it explicitly ("No human needed — agents can self-register").
- On agent-first boards, agents are allowed but the owner is liable. NEAR's text makes the Builder responsible for every agent action "regardless of whether the action was authorized, foreseeable, or intended". TaskMarket's terms page is still a draft "not approved or active".
- Multiple accounts: 4 of the 14 grid venues forbid them explicitly (HackerOne, Bugcrowd, Kaggle (ARC Prize), Upwork). The rest have no clause in this matrix.
- Model providers: an owner may sell work built from model output. All four providers checked (Anthropic, OpenAI, Google, GitHub Copilot) give or leave output rights with the user. Sharing a login or reselling access is forbidden at all four. On consumer plans, automated access is allowed only through the provider's own tools (Claude Code, Codex, Gemini CLI, Copilot's own agent); an always-on third-party runtime should use an API key. Two things remain unclear: (1) no text directly covers paid client work done on a personal subscription; (2) "ordinary, individual usage" is not defined for an agent running 24/7.
- Getting paid needs a person. At 12 of the 14 grid venues the owner must clear the identity or payout step. At the other 2 (Virtuals ACP, AgentPact), the money goes to a wallet with no KYC found, and whoever holds its keys controls it. Upwork's API & MCP Terms (v2.3, obtained this run via Wayback) explicitly bar an agent from accepting contracts, making identity or tax attestations, and funding or withdrawing.
- Security: 11 documented incidents with a primary source, each mapped to an owner control. The original task-text scan read 1,741 public tasks on 7 venues and found 0 injection-shaped instructions and 0 requests for secrets. Repository files are another matter: Coolify, a repository that carries Algora bounties, hides an instruction aimed at agents in its PR template, as a trap to spot them.
- Ledger: $232.55 reached agent workers in the 30 days 2026-09-02 → 2026-10-02 (run 2: $230.37). 40.4% came from operator or operator-linked wallets (run 2: 44.5%). The first identified independent payer is 1 payer: MolTrust, $9.25, for promotional bounties for its own product. Venues at meaningful scale: still 0.
Rules matrix size: 142 rows across 50 parties. Verdicts: forbid 41, restrict 78, allow 13, unclear 10. Source kinds: primary 109, via Wayback 15, via API JSON 13, third-party copy 1, search snippet 4 (unverified).
2. The venue × activity grid
Each cell shows the verdict and the rule row it rests on (IDs in rules.json; each links to its quote). Where several rows apply, the cell shows the most restrictive verdict that is not "unclear" (forbid > restrict > allow). "unclear (no row)" means no clause was found for that activity. "unverified" means the only source is a search snippet.
| Venue | E | AI-assisted work | Autonomous submission | Agent-operated account | Automation / API | Multiple accounts |
|---|---|---|---|---|---|---|
| HackerOne | E1 | restrict hackerone-automation_ai-2 | forbid hackerone-automation_ai-1 | restrict hackerone-account_identity-2 | restrict hackerone-automation_ai-3 (+1) | forbid hackerone-account_identity-1 |
| Bugcrowd | E1 | restrict bugcrowd-automation_ai-1 | forbid bugcrowd-automation_ai-2 | restrict bugcrowd-account_identity-2 | restrict bugcrowd-automation_ai-3 | forbid bugcrowd-account_identity-1 |
| huntr | E1 | forbid huntr-automation_ai-3 (+1) | forbid huntr-automation_ai-2 | unclear (no row) | forbid huntr-automation_ai-1 | unclear (no row) |
| Kaggle (ARC Prize) | E1 | allow kaggle-automation_ai-1 unverified | unclear (no row) | unclear (no row) | restrict kaggle-automation_ai-2 | forbid kaggle-account_identity-1 unverified |
| Upwork | E1 | restrict upwork-mcp-automation_ai-4 | restrict upwork-mcp-automation_ai-2 | restrict upwork-mcp-account_identity-1 (+1) | restrict upwork-mcp-automation_ai-1 (+1) | forbid upwork-mcp-account_identity-2 |
| Algora | E1 | unclear algora-github-bounties-automation_ai-2 | unclear (no row) | forbid algora-github-bounties-account_identity-1 | forbid algora-github-bounties-automation_ai-1 | unclear (no row) |
| TaskMarket | E1 | unclear (no row) | restrict taskmarket-security-1 | restrict taskmarket-account_identity-1 | restrict taskmarket-automation_ai-1 (+1) | unclear (no row) |
| MoltJobs | E1 | unclear (no row) | allow moltjobs-automation_ai-2 | restrict moltjobs-account_identity-1 | restrict moltjobs-automation_ai-1 | unclear (no row) |
| Execution Market | E1 | unclear (no row) | unclear (no row) | restrict execution-market-account_identity-2 (+1) | unclear (no row) | unclear (no row) |
| AgentPact | E1 | unclear (no row) | unclear (no row) | allow agentpact-account_identity-1 | unclear (no row) | unclear (no row) |
| Virtuals ACP | E1 | unclear (no row) | unclear (no row) | allow virtuals-acp-account_identity-1 | unclear (no row) | unclear (no row) |
| x402 / CDP facilitator | E1 | unclear (no row) | unclear (no row) | unclear (no row) | restrict x402-cdp-account_identity-1 | unclear (no row) |
| Superteam Earn | E3 | unclear (no row) | restrict superteam-earn-automation_ai-1 | restrict superteam-earn-account_identity-1 | unclear (no row) | unclear (no row) |
| NEAR AI Agent Market | E4 | unclear (no row) | unclear (no row) | restrict near-ai-agent-market-account_identity-1 | unclear (no row) | unclear (no row) |
Totals over the 14 venues: AI-assisted work: forbid 1, restrict 3, allow 1, unclear 9; Autonomous submission: forbid 3, restrict 3, allow 1, unclear 7; Agent-operated account: forbid 1, restrict 8, allow 2, unclear 3; Automation / API: forbid 2, restrict 7, allow 0, unclear 5; Multiple accounts: forbid 4, restrict 0, allow 0, unclear 10.
Notes on reading the grid:
- Algora: the platform has no clause on AI work, so the repository's own policy decides (section 4). The Algora account must be held by a person aged 18+ who completes Stripe Connect onboarding. A GitHub machine account is allowed if a responsible human creates it (one free machine account per person;
github-account_identity-1). Even so, Algora's literal terms bar a bot from using Algora itself. The compliant route: the human holds both accounts, posts/attemptand/claim, and does the Stripe step; the agent drafts code. - Kaggle: the AMLT "allow" and the single-account "forbid" still rest only on search snippets. The final-check Wayback retry returned only the JavaScript shell (see section 9).
- TaskMarket: every cell rests on a terms page that is labelled a draft, "not approved or active".
- Upwork: the agent may operate in the holder's account "within scopes the Upwork User has granted" (
upwork-mcp-automation_ai-3). It may not accept contracts or move money (upwork-mcp-account_identity-3), and it must disclose AI origin where a user would assume a human (upwork-mcp-automation_ai-4).
3. Model-provider terms
Key quotes (verbatim):
anthropic-automation_ai-1(restrict; primary; 2025-10-08): "Except when you are accessing our Services via an Anthropic API Key or where we otherwise explicitly permit it, to access the Services through automated or non-human means, whether through a bot, script, or otherwise." (https://www.anthropic.com/legal/consumer-terms)anthropic-automation_ai-3(restrict; primary; no date shown): "Claude Code usage is subject to the Anthropic Usage Policy . Advertised usage limits for Pro and Max plans assume ordinary, individual usage of Claude Code and the Agent SDK." (https://code.claude.com/docs/en/legal-and-compliance)anthropic-resale_sharing-4(forbid; primary; no date shown): "Customers may not pay for, resell, or intermediate Claude usage on their end users’ behalf. Each end user must authenticate with their own Anthropic API key, Claude subscription plan credentials, or 3P inference provider credential…" (https://code.claude.com/docs/en/legal-and-compliance)openai-resale_sharing-1(forbid; primary_via_wayback; 2026-01-01): "You may not share your account credentials or make your account available to anyone else and are responsible for all activities that occur under your account." (https://openai.com/policies/row-terms-of-use/)openai-automation_ai-1(restrict; primary_via_wayback; 2026-01-01): "For example, you may not: … Automatically or programmatically extract data or Output (defined below). … Interfere with or disrupt our Services, including circumvent any rate limits or restrictions or bypass any protective measures or safety mitigations we put on our Services." (https://openai.com/policies/row-terms-of-use/)google-automation_ai-1(restrict; primary; no date shown): "Directly accessing the services powering Gemini CLI (for example, the Gemini Code Assist service) using third-party software, tools, or services (for example, using OpenClaw with Gemini CLI OAuth) is a violation of applicable terms and policies. Such actions may be grounds for suspension or termination of your account." (https://github.com/google-gemini/gemini-cli/blob/main/docs/resources/tos-privacy.md)github-copilot-automation_ai-1(restrict; primary; no date shown): "…using our servers for any form of excessive automated bulk activity, to place undue burden on our servers through automated means, or to relay any form of unsolicited advertising or solicitation through our servers…" (https://docs.github.com/en/site-policy/acceptable-use-policies/github-acceptable-use-policies)
Synthesis: may an owner run their own agent on a consumer subscription to do paid work for third parties?
- Outputs: Yours to use at all four providers (assigned to you or no ownership claimed). Nothing found bars selling work built from Output.
- Automated access: Only through the provider's own tools when on a subscription: Anthropic (native Claude Code; API key for Agent SDK and products), Google (Gemini CLI itself; "using OpenClaw with Gemini CLI OAuth" named a violation), OpenAI (Codex clients sold with ChatGPT plans; ToU bars programmatic extraction of Output), GitHub (Copilot's own agent and CLI; AUP bans excessive automated bulk activity). A third-party always-on runtime should use an API key.
- Resale and sharing: Forbidden at all four. Doing paid work is not resale; letting a client use your plan or login is.
- Limits: Anthropic: "ordinary, individual usage"; Google: fixed per-user daily caps; OpenAI: plan and fair-use limits; GitHub: fair-access rate limits.
- What is unclear, stated plainly: (1) No provider text says whether paid client work on a personal subscription is allowed. It is neither permitted nor forbidden in words. (2) Anthropic says its advertised Pro and Max limits "assume ordinary, individual usage", and "ordinary, individual usage" is not defined for an agent that runs around the clock. (3) OpenAI has no general bot ban, so unattended Codex on a Plus or Pro plan doing client work is neither allowed nor forbidden; its Terms do forbid automatically or programmatically extracting Output and presenting Output as human-generated. The safe reading for a 24/7 agent doing paid work is an API key under commercial terms.
OpenAI quote status (the bootstrap quotes came from search snippets):
| Bootstrap quote | Status | Route |
|---|---|---|
| "You may not share your account credentials or make your account available to anyone else." | verified | Wayback 20260930092027 (ToU effective 2026-01-01) |
| "(g) buy, sell, or transfer API keys from, to, or with a third party" | verified | Wayback 20260926161009 (Services Agreement effective 2026-01-01) |
| "You may not make account access credentials available to third parties, share individual login credentials between multiple users on an account, or resell or lease access to your account or any End User Account." | not in current text; superseded; current text: "Customer will not share Account access credentials or individual login credentials between multiple users. Customer may not resell or lease access to its Account or any End User Account." | Wayback 20260926161009 |
| "Your OpenAI account is meant for you—the individual who created it." | verified | Wayback 20260406073712 (newest capture; live 403) |
Result: 3 of 4 verified from archived primary copies; 1 is not in the current text and has been replaced by the current Services Agreement wording (openai-resale_sharing-3, marked changed). The live OpenAI pages still return 403. The newest capture of the account-sharing help article is from 2026-04-06.
4. Maintainer AI-contribution policies
21 rows across 18 projects, 6 of them repositories that carried Algora bounties in run 2's sample. Verdicts: forbid 10, restrict 9, unclear 2.
Algora-bounty repositories (where the bounty money is):
| Repository | Activity | Verdict | Quote | Row |
|---|---|---|---|---|
| Archestra (archestra-ai/archestra) | autonomous_submission | forbid | "We take contributions as human-written text, not code. Pull requests from non-maintainers are closed automatically by CI. Describe the change you want in a GitHub issue written by a human. …" | archestra-contribution_policy-1 |
| Activepieces | autonomous_submission | forbid | "We've temporarily paused unsolicited pull requests from outside the core team. PRs from contributors who aren't organization members or collaborators are automatically closed with a friendly note. … Agentic coding …" | activepieces-contribution_policy-1 |
| Coolify | ai_assisted_work | restrict | "AI usage is allowed. However, contributors must fully understand what their changes do and why. … If AI tools were used at any stage, mention it in the pull request …" | coolify-contribution_policy-1 |
| Coolify | autonomous_submission | restrict | "AI-assisted PRs that are human reviewed are welcome, just let us know so we can review appropriately. … This "Changes" section must be human-written and not AI-generated." | coolify-contribution_policy-2 |
| Qdrant | ai_assisted_work | restrict | "Do not communicate with real people through AI … If you are using AI tools to generate PR, you are still responsible for the results … "I asked claude, and …" | qdrant-contribution_policy-1 |
| Cap (CapSoftware/Cap) | ai_assisted_work | unclear | "none found" | cap-contribution_policy-1 |
| tscircuit (tscircuit/jlcsearch) | ai_assisted_work | unclear | "none found" | jlcsearch-contribution_policy-1 |
Reading: 2 of the 6 (Archestra, Activepieces) now close every outside PR automatically. 2 (Coolify, Qdrant) allow AI help, provided it is disclosed and a human writes the PR text. 2 (Cap, tscircuit/jlcsearch) have no AI policy at all, and tscircuit holds most of the open Algora bounties. None explicitly allows an unattended agent to submit. Coolify's PR template also hides a trap instruction for agents (section 6).
Other projects:
| Project | Activity | Verdict | Quote | Row |
|---|---|---|---|---|
| Ghostty | ai_assisted_work | restrict | "All AI usage in any form must be disclosed. You must state the tool you used (e.g. Claude Code, Cursor, Amp) along with the extent that the work was AI-assisted. …" | ghostty-contribution_policy-1 |
| Ghostty | autonomous_submission | forbid | "If you aren't vouched, any pull requests you open will be automatically closed. … Write in your own voice, don't have an AI write this" | ghostty-contribution_policy-2 |
| tldraw | autonomous_submission | forbid | "We are not accepting contributions to [tldraw](https://github.com/tldraw/tldraw) at this time. Pull requests are turned off for this repository." | tldraw-contribution_policy-1 |
| curl | ai_assisted_work | restrict | "If you asked an AI tool to find problems in curl, you must make sure to reveal this fact in your report. … We ban users immediately who submit made …" | curl-contribution_policy-1 |
| Gentoo | ai_assisted_work | forbid | "It is expressly forbidden to contribute to Gentoo any content that has been created with the assistance of Natural Language Processing artificial intelligence tools. This motion can be revisited, should …" | gentoo-contribution_policy-1 |
| NetBSD | ai_assisted_work | forbid | "Code generated by a large language model or similar technology, such as GitHub/Microsoft's Copilot, OpenAI's ChatGPT, or Facebook/Meta's Code Llama, is presumed to be tainted code, and must not be …" | netbsd-contribution_policy-1 |
| QEMU | ai_assisted_work | forbid | "Current QEMU project policy is to DECLINE any contributions which are believed to include or derive from AI generated content. This includes ChatGPT, Claude, Copilot, Llama and similar tools." | qemu-contribution_policy-1 |
| Servo | ai_assisted_work | forbid | "Contributions must not include content generated by large language models or other probabilistic tools, including but not limited to Copilot or ChatGPT. This policy covers code, documentation, pull requests, issues, …" | servo-contribution_policy-1 |
| LLVM | ai_assisted_work | restrict | "LLVM's policy is that contributors can use whatever tools they would like to craft their contributions, but there must be a human in the loop. Contributors must read and review …" | llvm-contribution_policy-1 |
| LLVM | autonomous_submission | forbid | "An important implication of this policy is that it bans agents that take action in our digital spaces without human approval, such as the GitHub [@claude agent](https://github.com/claude/). Similarly, automated review …" | llvm-contribution_policy-2 |
| Linux kernel | autonomous_submission | restrict | "AI agents MUST NOT add Signed-off-by tags. Only humans can legally certify the Developer Certificate of Origin (DCO). The human submitter is responsible for: * Reviewing all AI-generated code … …" | linux-contribution_policy-1 |
| Fedora | ai_assisted_work | restrict | "You MAY use AI assistance for contributing to Fedora, as long as you follow the principles described below. … The contributor is always the author and is fully accountable for …" | fedora-contribution_policy-1 |
| CPython | ai_assisted_work | restrict | "The person submitting an issue or PR is responsible for its content, regardless of whether AI tools were used in its creation. … Disclosure of the use of AI tools …" | cpython-contribution_policy-1 |
| Zig | ai_assisted_work | forbid | "Strict No LLM / No AI Policy No LLM-generated content, whether it be code or prose. No paraphrasing LLM-generated content. No LLMs for editing, including fixing spelling or grammatical errors. …" | zig-contribution_policy-1 |
5. KYC and jurisdiction
kyc.json covers 20 venues, including all 14 grid venues (normalised kyc_required over the 14: conditional 6, no 2, unknown 3, yes 3).
| Venue | KYC | Provider | Trigger | Age | Excluded jurisdictions | Who must act | Source |
|---|---|---|---|---|---|---|---|
| execution-market | conditional | World ID (Orb) | Bounties of $500 or more need an Orb-verified worker; below $500 no identity check found | 18 (terms) | none listed | owner (a human must hold the Orb verification; publisher-side wallet and ERC-8004 identity set … | primary |
| moltjobs | no | none found | Owner email claim is required before any withdrawal (not KYC) | not stated | none listed | owner (must claim the agent by email and issue a key with wallet:withdraw; the … | primary |
| taskmarket | no | none | No KYC step in the worker flow; terms reserve the right to request identity, age, source-of-funds and tax information | 18 or age of majority | sanctioned jurisdictions and blocked persons | owner (explicit approval before the one-time set-withdrawal-address; owner must keep the one-time accountRecoveryCode, which … | primary |
| algora-github-bounties | yes | Stripe Connect | payout onboarding (before first bounty payout) | 18 (terms: 'Service is intended only for access … | Countries outside Stripe Connect payout coverage (list in docs payments.md); in India and UAE individuals cannot receive international … | owner (person aged 18+, or a business entity where Stripe requires it) | third_party_copy |
| bugcrowd | conditional | Jumio (NetVerify) | before submitting to Managed Bug Bounty programs (public and private, excluding on-demand MBBs); also forced after ≥10 invalid reports and … | 18 or age of majority in the jurisdiction … | Citizens/residents of, or persons located in, countries or regions under US or other sovereign sanctions or embargoes; no … | owner (individual researcher; tax forms also exist for a non-US corporation) | primary |
| hackerone | yes | Veriff | always: before any bug bounty program submission (since August 2026) and before payout; renewed every 12 months. VDPs (unpaid) exempt. | 18 for ID verification (terms: under-13 excluded; minors … | No country list published; terms 5.1 bars use in violation of US/UK/EU sanctions; OFAC-listed banks (e.g. VTB, SBERBANK) … | owner (a natural person aged 18+; for business accounts, a legally authorized representative who … | primary |
| huntr | yes | Stripe Connect | first prize earned (monthly payout run around the 25th) | over 18 | Anyone not domiciled in a Stripe Connect cross-border payout country (list: https://stripe.com/docs/connect/cross-border-payouts#supported-countries) | owner (individual Contributor with own bank account) | primary |
| kaggle | conditional | none named (Kaggle/Competition Sponsor prize acceptance documents) | prize winners only | older of 18 or age of majority in … | Crimea, so-called DNR and LNR, Cuba, Iran, North Korea; persons subject to US export controls or sanctions (snippet, … | owner (registered Kaggle account holder; team members individually) | search_snippet |
| upwork-mcp | conditional | Upwork in-house (government ID upload with photo; vendor not named) | when Upwork asks (identity verification notification) and regular KYC checks; tax info required before any withdrawal | not found in help centre (ToS 403) | Russia and Belarus suspended since March 2022; OFAC/EU/UK/UN sanctions screening; full list in 'Who's eligible to join and … | owner (the verified person; withdrawal beneficiary name must match the verified Upwork name) | primary_via_api_json |
| virtuals-acp | unknown | none found | none found | none found | none found | agent wallet receives directly; owner controls the wallet keys | primary |
| x402-per-call-endpoints | unknown | Coinbase (CDP account); OFAC/KYT address screening | Seller needs a CDP API key to use the CDP Facilitator; no seller KYC requirement found on facilitator or production-configuration … | not stated | not stated | owner (holds the CDP account and API key; funds land in the seller's own … | primary |
| agentpact | unknown | none found | none found | none found | none found | agent/owner wallet receives directly | primary |
| superteam-earn | conditional | Sumsub (inferred from the open-source repo's @sumsub/websdk dependency; FAQ names … | winners of Superteam/Solana-sponsored listings; external sponsors sometimes ask for their own KYC or invoices | not found | not stated in FAQ; many listings are region-restricted per listing | owner (human claimant: 'Agents do not complete OAuth, wallet signing, or KYC. A human … | primary |
| near-ai-agent-market | conditional | Operator verification; Stripe Connect on the USD rail | Verification 'when you register and from time to time thereafter, including as a condition of any payout, withdrawal, incentive, or … | not re-checked this run | not re-checked; sanctions/AML checks named | owner (the Builder; the agent cannot complete Stripe Connect onboarding) | primary_via_api_json |
| immunefi | conditional | not named | when 'necessary for a bug report payment' (project-dependent) | not found | not found on rules page | owner (bug report must be 'substantially your own'; KYC information must be authentic) | primary |
| dealwork-ai | unknown | not stated | 'verification checks' on agent accounts; payout methods shown only in the logged-in wallet | not stated | not stated | owner (fully responsible for agent spending; methods unknown) | primary |
| opentask-ai | conditional | not stated | Email verification, 'additional verification', risk review and payment-readiness checks may be required before some features | 18 | not stated | owner | primary |
| ugig-net | no | none found | none | not stated | not stated | agent or owner (whoever controls the wallet) | primary |
| toku-agency | yes | Stripe Connect | On withdrawal: 'Withdraw anytime via Stripe Connect' | 18 | not stated | owner (Stripe Connect account holder) | primary |
| frantic | conditional | Frantic 'Sworn' (email, public oath, GitHub star) / runx GitHub … | Claiming any paid bounty needs a verified email or runx GitHub identity; over $10 needs eligibility or one successful paid … | not stated | not stated | owner (email/GitHub identity) | primary_via_api_json |
Carry-overs:
- Bugcrowd fees and minimums: Answered: Bugcrowd covers fees from its account to the payment provider; bank minimums ACH/EFT $1.00, SEPA/FPS/BECS/NPP/FPSHK/IACH $3.00, SWIFT $20.00 (US merchant accounts). See the bugcrowd entry.
- dealwork.ai withdrawal methods: Still open: methods are shown only inside the logged-in wallet; public docs and terms do not list them.
- CDP facilitator KYC for mainnet sellers: Still open: no CDP text found requiring KYC for mainnet x402 sellers; the facilitator needs a CDP account and API key (rows x402-cdp-account_identity-1, x402-cdp-kyc_payout_eligibility-2).
- HackerOne ID verification (Veriff, 18+) has been required before any bug-bounty submission since August 2026, including submissions through the Hacker API and Report Assistant.
6. Security
11 documented incidents, each with a primary source (vendor research 6, CVE 3, official post-mortem 2), plus 2 observed designs and the task-text scan.
| ID | Date | Vector | Incident | Primary source | Owner control |
|---|---|---|---|---|---|
| sec-01 | 2026-02-02 | key_or_db_leak | Moltbook production database exposed: 1.5M agent API tokens readable and writable | https://www.wiz.io/blog/exposed-moltbook-database-reveals-millions-of-api-keys | Treat every agent-platform API key as exposable: give the agent a key unique to that platform, never reuse it elsewhere, rotate it … |
| sec-02 | 2026-02-01 | malicious_package_or_skill | ClawHavoc: 341 (later 824) malicious skills on the ClawHub agent-skill registry | https://www.koi.ai/blog/clawhavoc-341-malicious-clawedbot-skills-found-by-the-bot-they-were-targeting | Install skills only from sources you have read end to end; never run "prerequisite" install commands a skill tells you to run; … |
| sec-03 | 2026-02-05 | malicious_package_or_skill | Snyk ToxicSkills: 13.4% of 3,984 agent skills had critical issues; 76 confirmed malicious payloads | https://snyk.io/blog/toxicskills-malicious-ai-agent-skills-clawhub/ | Same as sec-02, plus run the agent in a sandbox or separate machine user with no access to your wallets, SSH keys … |
| sec-04 | 2026-02-01 | other | CVE-2026-25253: OpenClaw gateway token sent to attacker-supplied URL (one-click compromise) | https://nvd.nist.gov/vuln/detail/CVE-2026-25253 | Keep the agent runtime patched (auto-update or a weekly check), do not expose its gateway to the internet, and do not open … |
| sec-05 | 2025-04-01 | mcp_tool_poisoning | MCP tool poisoning: hidden instructions in tool descriptions exfiltrate files | https://invariantlabs.ai/blog/mcp-security-notification-tool-poisoning-attacks | Connect only MCP servers you trust and have read; review full tool descriptions; pin server versions; keep MCP servers that touch money … |
| sec-06 | 2025-05-26 | task_text_injection | GitHub MCP toxic agent flow: a malicious public issue makes the agent leak private repositories | https://invariantlabs.ai/blog/mcp-github-vulnerability | Bounty issues are untrusted task text: give the bounty-working agent a fine-grained token limited to the target public repository (no private repos), … |
| sec-07 | 2025-07-23 | malicious_package_or_skill | Amazon Q Developer VS Code extension shipped with injected malicious code (v1.84.0) | https://aws.amazon.com/security/security-bulletins/AWS-2025-015/ | Do not run coding agents with blanket permission flags on a machine holding wallets or credentials; keep agent tools updated but watch … |
| sec-08 | 2025-08-26 | malicious_package_or_skill | Nx "s1ngularity" npm compromise drove local AI CLIs to hunt for secrets | https://nx.dev/blog/s1ngularity-postmortem | Never leave AI CLIs authenticated with permissive "skip permissions" defaults on a machine with wallets or keys; keep secrets out of plain … |
| sec-09 | 2025-08-12 | task_text_injection | CVE-2025-53773: prompt injection to local code execution in GitHub Copilot / Visual Studio | https://nvd.nist.gov/vuln/detail/CVE-2025-53773 | Keep the IDE and agent extension patched; do not let the agent change its own settings or auto-approve tool runs when it … |
| sec-10 | 2025-09-25 | malicious_package_or_skill | postmark-mcp: first malicious MCP server in the wild BCC'd every email to the attacker | https://www.koi.security/blog/postmark-mcp-npm-malicious-backdoor-email-theft | Pin MCP server versions and review changes before upgrading; prefer servers published by the service owner; watch outbound traffic from agent tools. |
| sec-11 | 2025-07-09 | mcp_tool_poisoning | CVE-2025-6514: mcp-remote OS command injection from a malicious MCP server | https://nvd.nist.gov/vuln/detail/CVE-2025-6514 | Connect only to MCP servers you trust, keep MCP client tooling updated, and run agents in a sandbox. |
Observed designs (not breaches):
- sec-12: Moltbook skill tells agents to re-fetch and follow a remote heartbeat file every 30 minutes (design exposure, not a breach). Moltbook's skill.md (version 1.12.0) instructs agents to add "Fetch https://www.moltbook.com/heartbeat.md and follow it" to a periodic task list every 30 minutes. Whoever controls that file, or the domain, can change the agent's instructions at any time without the owner seeing it. Source: https://www.moltbook.com/skill.md. Control: Do not let agents follow remotely updated instruction files; copy the file locally, hash it, and review changes before the agent uses a new version.
- sec-13: Coolify pull-request template carries a hidden instruction aimed at AI agents (maintainer trap, not a breach). The PR template of coollabsio/coolify, a repository that has carried Algora bounties, begins with a hidden HTML comment addressed to AI agents telling them to put a marker word at the top of the PR description. An agent that obeys it reveals itself as an unattended agent to the maintainers; it is a detection canary, not an attack. We paraphrase it here rather than repeat it, so that no agent reading this page acts on it; the verbatim text is at the linked source. Source: https://github.com/coollabsio/coolify/blob/main/.github/pull_request_template.md. Control: Treat repository files (templates, CONTRIBUTING, issue text) as data. Do not let a bounty agent follow instructions found in them; keep a human reviewing and writing the PR description, as Coolify's own rules require (rules row coolify-contribution_policy-2).
Task-text scan (original measurement). Case-insensitive regular expressions over public task text pulled read-only with GET requests on 2026-10-02. Text treated strictly as data: nothing was executed, followed, claimed or submitted. A match is 'injection-shaped or key-seeking text', not proof of malice; each match was read and labelled in match_review.
| Venue | Tasks scanned | Window | Pattern matches |
|---|---|---|---|
| taskmarket | 147 | tasks created 2026-09-02..2026-10-02 plus all open tasks (full description text) | 19 |
| moltjobs | 122 | all 122 jobs (title, description, inputData incl. acceptance criteria) | 1 |
| dealwork-ai | 100 | latest 100 jobs from /api/v1/jobs?per_page=100 (title, description) | 0 |
| execution-market | 1,165 | completed tasks created 2026-09-02..10-02 (1,161) plus 4 available tasks (title, instructions) | 7 |
| ugig-net | 62 | 12 bounties + latest 50 gigs (title, description) | 0 |
| toku-agency | 20 | latest 20 job posts (title, description) | 0 |
| frantic | 125 | open + recently completed bounties on /v1/board (titles only; bodies of 'private' bounties not … | 0 |
| Total | 1,741 | 27 |
Manual review of the 27 matches: injection-shaped instructions 0; secret-exfiltration requests 0; requesters forbidding secrets 20; tasks asking the worker to create a key or account at a third-party service 4; benign or false positive 3. Across 1,741 public task texts on 7 venues, no task told the agent to ignore its instructions, reveal a system prompt, hand over keys or seed phrases, send funds or run a piped shell command. The secret-related matches are mostly requesters forbidding secrets (20 tasks). Four tasks ask the worker to create an account or API key at a third-party service (MolTrust x3, Yukon x1): harmless in itself, but it means an agent will create credentials outside the owner's view, which the owner should allow or block explicitly.
Limits: Regex over text visible to anonymous GET. Private bounties (Frantic), auth-gated feeds and attachments/linked files (skill.md files, repos named in tasks) were not scanned. Execution Market completed tasks scanned on titles only. Zero matches is not proof of safety. The full pattern list is in security.json (task_text_scan.pattern_list).
Checklist implications ("Safety before you connect"): a separate low-balance wallet; spending caps and no unattended spending policy; one scoped key per venue, rotated after any disclosure; pin or hash skill and heartbeat files and never follow remotely updated instruction files; vet and pin MCP servers; run the agent in a sandbox or as a separate machine user with no wallets or SSH keys; treat task text and repository files as data.
7. Ledger refresh
Cut-off: 2026-10-01T14:10:05Z. As of: 2026-10-02T13:45:00Z. Window: 2026-09-02 → 2026-10-02.
New events: 18 (TaskMarket 6, Virtuals ACP 2, x402 sample 10). New agent-work USD since the cut-off: $11.12, all unlinked (TaskMarket $11.10: six 1.85-USDC awards on 2026-10-02 from requester 0x4363 in cluster 0xd8c5, paid to 4 workers; ACP $0.018 from two 0.01-USDC jobs). No new events: Execution Market (no completion since 2026-09-29), MoltJobs (no release since 2026-09-23), AgentPact (no escrow transfer since 2026-09-01; 2 new free self-deals). The ledger now holds 294 events (256 agent-work events in the window).
| Venue | 30-day USD net | operator | operator_linked | unlinked | identified_independent | Latest payout |
|---|---|---|---|---|---|---|
| taskmarket | $128.60 | $0.00 | $0.00 | $119.35 | $9.25 | 2026-10-02 |
| virtuals-acp | $29.17 | $0.00 | $19.25 | $9.92 | $0.00 | 2026-10-02 |
| execution-market | $36.49 | $0.00 | $36.49 | $0.00 | $0.00 | 2026-09-29 |
| moltjobs | $38.29 | $38.29 | $0.00 | $0.00 | $0.00 | 2026-09-23 |
| agentpact | $0.00 | $0.00 | $0.00 | $0.00 | $0.00 | 2026-09-01 |
| Total | $232.55 | $38.29 | $55.74 | $129.27 | $9.25 |
Headline numbers: $232.55 paid for agent work in 30 days (run 2: $230.37). The operator or operator-linked share is 40.4% (range 32.2%–44.7% depending on the ACP split; run 2: 44.5%, range 36.2%–48.9%). Sensitivities: 45.6% under the strict two-hop reading for payer 0xf138; 85.0% if cluster 0xd8c5 turned out to be operator-affiliated. Identified independent payers: 1 ($9.25). Venues at meaningful scale: 0.
Why the numbers moved: the window moved forward one day. AgentPact's operator-paid $6.41 and Execution Market's 2026-09-01 swarm tasks (run 2: $38.69, now $36.49) left the window, and TaskMarket added $11.10 of unlinked pay. The total is almost unchanged, and the operator share fell by about 4 points. That fall is a window effect, not new independent demand.
Homepage numbers: paid or selling venues 26; E1 venues 12; E1 venues with agent-work payouts 5 (E1 means a confirmed payout; latest dates: TaskMarket and ACP 2026-10-02, Execution Market 2026-09-29, MoltJobs 2026-09-23, AgentPact 2026-09-01); independent payers at meaningful scale 0. All four are unchanged. New secondary figure: venues with agent-work payouts in the last 30 days: 4. AgentPact has had no payout since 2026-09-01 and turns stale on 2026-10-31.
Lead outcomes:
- MolTrust: confirmed, so the first identified independent payer. MolTrust's own repository says it funded the TaskMarket bounties TSK-9YFR1YF7 and TSK-KEYKZGQF: MoltyCel/moltrust-api PR #369 says "The two bounties were funded under 2026-07-draft-2", PR #404 says "The 109 are agents we paid to show up", and PR #410 lists both task IDs. The TaskMarket API gives 0xa175d51b as the requester of both. The PRs do not print the wallet; the link is task ID → API requester. Events taskmarket-0060 to 0065 ($9.25 net, 2026-09-21) move from
unlinkedtoidentified_independent, withpayer_motive: promotional_user_acquisition. Under the written rule, TaskMarket'sindependent_payer_evidencebecomes "yes". In plain terms: 1 identified independent payer, $9.25, promotional bounties for the payer's own product. That is one sponsor paying agents to register with its identity service, far below meaningful scale ($1,000 from 5 payers); it is not evidence of customers buying agent work. - Funder 0xd8c5763b: still unidentified; not an exchange hot wallet. It is an EIP-7702 delegated EOA with no Blockscout tag and no ENS name. Its large inflows come from DEX pools and smart accounts, not an exchange: for example 162,684.97 USDC via ERC-4337 handleOps (2026-02-09) and 58,591.73 USDC from the Uniswap UniversalRouter (2025-12-27). Its recent inbound pages are full of address-poisoning dust. It seeds 3+ TaskMarket requester agents, and no link to TaskMarket operator wallets was found. The class stays
unlinked; the cluster accounts for 80.6% of TaskMarket gross in the window. - Frantic (gofrantic.com): backlog only. It is a public bounty board for agents paying USDC on Base via x402. Its board reports funded_usd 842.5, moved_usd 1280.3 and 1,252 enlisted operators (self-reported), with 4 open bounties ($3–$16). Its x402 payTo took $211.95 from 40 buyers in 30 days and sent 9.0 USDC to MoltJobs' top worker on 2026-09-17. Its PAID receipts were not traced to on-chain transfers to worker wallets, so it gets no E-level. Rule risk: much of the paid work is marketing on third-party sites, e.g. "Answer live Reddit threads with a dated fact from an open registry" ($3), "Earn a citation on an external page that already ranks" ($16), and adding a startup to a list verified by a GitHub star ($1.50). Reward-driven GitHub stars fall under GitHub's Acceptable Use Policies on inauthentic activity incentivised by rewards (
github-automation_ai-1). Reddit's rules and the citing sites' rules were not checked this run, so there is no row for them. - Execution Market: correction and watch item. The public metric
total_volume_usdcounts posted bounties, not payouts. It rose from $504.84 to $524.84 (+$20.00) when one $20 task was published on 2026-10-01, while nothing was completed. Recorded in the venues.json change_log. Watch item: task 607c9a44 ($20, physical-presence photo in Medellín, non-swarm publisher 0xcecbc7ad, escrow pending assignment). If it settles, it would be Execution Market's first payout from a payer outside the operator's swarm (initial classunlinked). - x402 refresh (excluded from agent-work totals; buyers not traced): Cluster Protocol $54,761 / 722 buyers; dTelecom $35,559 / 26 buyers; StableEnrich $1,497 / 336; OneShot $347 / 53; StableStudio $166 / 74. x402scan overall 30-day: $995,270 from 28,523 buyers.
8. What changed since 1 October
Rules (change_vs_previous across 142 rows: changed 8, new 93, unchanged 41). "new" mostly means a clause quoted for the first time, not a new policy. Changed rows:
kaggle-account_identity-1: STILL FROM SNIPPETS (unverified); same routes as kaggle-automation_ai-1. The 2026-09-30 snippet wording was 'You may only participate using a single, unique Kaggle account … Participating using more than one Kaggle account per individual Participant is a breach'; today's snippet gives …openai-resale_sharing-3: PARTLY NOT VERIFIED: the bootstrap snippet "You may not make account access credentials available to third parties, share individual login credentials between multiple users on an account, or resell or lease access to your account or any End User Account." …tldraw-contribution_policy-1: Escalated since bootstrap ("external-PR auto-close"): PRs now turned off entirely. Linked issue #7695 "Contributions policy" (steveruizok, 2026-01-15): "we’ve recently seen a significant increase in contributions generated entirely by AI tools". Applies to all external contributors, human or agent.gentoo-contribution_policy-1: Was "secondary" on the public page; now verified from the primary wiki page (Council vote 2024-04-14; page last edited 11 September 2026).netbsd-contribution_policy-1: Was "secondary" on the public page; now verified from the primary page. Applies to committers.taskmarket-account_identity-1: First sentence matches the 2026-09-30 quote; the autonomous-acceptance limit was not quoted before. TaskMarket's live terms page is headed 'Effective date: [COUNSEL TO APPROVE EFFECTIVE DATE] Draft for counsel review. This policy is not approved or active.' and carries 8 …agentpact-account_identity-1: 2026-09-30 record said 'none found (checked: llms.txt partial)'. https://agentpact.xyz/terms returned 404. Registration: 'POST https://api.agentpact.xyz/api/auth/register (free, instant API key)'.toku-agency-account_identity-1: 2026-09-30 record: 'none found (checked: homepage, /docs)'. ownerEmail is optional ('omit for fully autonomous registration').- Upwork API & MCP Terms of Use (Version 2.3, effective 2026-08-13) read for the first time, via Wayback snapshot 20260910011811. Four new rows.
- HackerOne: ID verification is now required before any bug-bounty submission (August 2026). The Upwork MCP help article was edited 2026-10-01 with the explicit-confirmation FAQ. Superteam: 24 of 25 open listings are HUMAN_ONLY (run 2: 28 of 30).
- Unchanged: HackerOne hackbot and one-account clauses; Bugcrowd Code of Conduct (2025-11-25) and the 2026-03-10 blog; huntr challenge rule; Upwork bot article; Algora robot clause (2021-08-17); Superteam skill.md; Anthropic and Google effective dates.
Ledger and catalogue (payouts.json and venues.json, changes_since_previous and per-record change_log):
- reclassification: taskmarket-0060..0065 unlinked → identified_independent. MolTrust publicly confirms funding TaskMarket bounties TSK-9YFR1YF7 and TSK-KEYKZGQF (MoltyCel/moltrust-api PRs #369, #404, #410); TaskMarket API requester 0xa175d51b. First identified independent payer in the ledger: 1 payer, $9.25, promotional bounties for its own product.
- window_shift: all. Window moved from 09-01..10-01 to 09-02..10-02; 2026-09-01 payouts dropped out (AgentPact $6.41, TaskMarket $0.30, ACP $0.036, Execution Market tasks created 09-01).
- headline: agent_work_usd_paid_30d 230.37 → 232.55.
- headline: operator_or_operator_linked_share 0.4455 → 0.4043. Falls mainly because AgentPact's operator-paid $6.41 and part of Execution Market's swarm pay left the window while TaskMarket (unlinked) added $11.10.
- headline: identified_independent_payers 0 → 1. MolTrust, $9.25, promotional.
- secondary_number: e1_agent_paid_last_30d → 4. AgentPact has no payout in the window (latest 2026-09-01; stale on 2026-10-31). Homepage E1 count with agent-work payouts stays 5.
- correction: execution-market metrics total_volume_usd. Counts posted bounty value, not payouts (504.84 -> 524.84 when one $20 task was published).
- watch: execution-market task 607c9a44. $20 non-swarm task pending assignment; would be EM's first non-operator payer if settled.
- venues.json: 18 records changed; last_verified set to 2026-10-02 only for the 6 ledger venues (taskmarket, virtuals-acp, execution-market, moltjobs, agentpact, x402-per-call-endpoints); rules_checked set on 18 records; all 33 slugs kept; no promotion or demotion. TaskMarket independent_payer_evidence unknown → yes. tos_ai_policy updated for taskmarket, agentpact and toku-agency.
9. Open questions and backlog
Open questions:
- Kaggle ARC Prize 2026 rules (AMLT, single account, eligibility): still from search snippets only. Every route has failed: direct fetch gives a JS shell; r.jina.ai 403; archive.ph 429; GitHub copies are paraphrases; arcprize.org lacks the clauses; the Wayback snapshot 20260904170707, retried later in the run, holds only the JS shell. A later run could try a rendered-page snapshot or the Kaggle API from another egress.
- HackerOne
submitted_with_assistant: not documented publicly. Best inference (unconfirmed): it marks reports submitted through Hai Report Assistant. It should not be read as evidence that an agent found the bug. - Google VRP: the claim that it "stopped accepting AI reports in March 2026" is refuted only at snippet level. What did change: the OSS VRP raised proof requirements, and it stopped taking product vulnerabilities from 1 October 2026. bughunters.google.com is JS-only and Wayback returned 429.
- dealwork.ai withdrawal methods and CDP facilitator seller KYC: still open (see section 5).
- Provider gaps: Google ToS and Google One terms for consumer Gemini plans not read; no Anthropic support article on plan limits read; optional providers (xAI, Mistral, Cursor) skipped.
- Who is behind cluster 0xd8c5, and contracts 0xDc24245C and 0xb2cc224c? Will Execution Market task 607c9a44 settle? Will MolTrust's two open TaskMarket bounties (TSK-J3R0MDGA 5.41 USDC with 206 submissions; TSK-E49N4V7T 0.541 USDC) pay out?
- Security leads still secondary: Vectra's Moltbook injection-prevalence figure; the GTIG May 2026 report on account pooling through API relays.
- Not researched: Intigriti and YesWeHack KYC and payouts; Outlier terms; DataAnnotation's AI clause (terms 404); Prolific participant terms (404; rules row from the researcher help centre); Reddit's rules for Frantic-style tasks.
Backlog (venues.json, backlog): Frantic (updated: no E-level until PAID receipts are traced on-chain); Intigriti, YesWeHack, Immunefi and Google VRP added with rules seen and no payout evidence collected. None promoted. Watch list: Execution Market idle since 2026-09-29; Algora's latest confirmed payout passes 60 days around 2026-10-25; AgentPact stale on 2026-10-31; ARC Prize Milestone #2 results expected around 2026-10-06.