MarketNow

io.github.alicelabs-llcv1.15.0更新于 Sep 29, 2026

Verify AI agent credentials, translate 9 formats, check scam domains, search 68k+ MCP servers.

已验证Streamable HTTP可网页运行Developer ToolsSecurity & MonitoringWeb Search & Scraping

概览

AI 生成的概览

让助手验证 AI 代理凭证、在多种格式间转换凭证、检查域名诈骗风险,并搜索已索引的 MCP 服务器注册表。

功能
提供九个 marketnow_* 工具:通过 12 阶段流水线验证 JWT、W3C VC、MCP Card、ATC v3、A2A、EAT-AI、ZTA、X.509 等代理凭证(R20),在八种格式间无损转换凭证(R21),列出支持的格式与流水线阶段(R22、R23),给出域名诈骗风险评分(R24),搜索已索引的 MCP 服务器注册表(R25),对照签名吊销注册表检查吊销状态(R26),用 JCS 与 SHA-256 对 MCP 工具定义做指纹(R27),并在校验与扫描后提交技能到目录(R28)。
适用场景
当助手需要在执行前判断某个 AI 代理、凭证或域名是否可信时适用,也适合查找和比较已索引的 MCP 服务器。需要凭证格式转换、吊销检查或工具定义指纹的工作流同样适用。它不是通用工具服务器。
运行要求
既可以作为远程 Streamable HTTP 端点连接(R31),也可以通过 npx marketnow-mcp(R32)或已发布的 Docker 镜像(R33)在本地运行。npm 包需要 Node.js,Docker 方式需要容器运行时。清单未声明认证、环境变量或请求头。托管工具需要能访问厂商端点。
安装前请注意
submit 工具会把技能发布到公开目录,发布前会做校验与扫描(R28),因此应视为公开提交。验证、翻译、域名检查与吊销检查会把所提供的凭证、域名或卡片标识发送到托管端点。清单未声明任何凭证或 API 密钥,但不要把机密或私钥粘贴进工具输入。

安装

在 SourceWeft 中

  1. 打开 控制台中的 MarketNow,将其添加到工作区。
  2. 为需要使用其工具的对话启用该服务。

Web executable,通过 Streamable HTTP。 远程服务在工作区中配置后即可从网页运行时运行。

其他 MCP 客户端

把它添加到你客户端的 mcpServers 配置中。

{
  "mcpServers": {
    "marketnow": {
      "type": "http",
      "url": "https://marketnow.site/api/mcp/"
    }
  }
}

README

MarketNow — Trust Infrastructure for AI Agents

Repo ecosystem (one owner per concern, split 2026-09-26):

RepoSole owner of
alicelabs-llc/MARKETNOW (this repo)Product code: mcp-server (npm marketnow-mcp), atc-sdk/atc-python/atc-rust, Docker/Cline/Cursor integrations, CLIs, security audits
eddyflores100-lang/marketnowLive marketplace: site (aep-marketplace/), catalog data (_data/, skills/, public/api/), the 21 scheduled data pipelines, Vercel deploys of marketnow.site
alicelabs-llc/universal-trust-adapterATC/1.0 protocol: spec, adapters, reference implementation, plugins
alicelabs-llc/marketnow-submissionsPublic skill submissions queue
alicelabs-llc/statusLive status page

Data and site questions go to the marketplace repo; protocol questions to UTA; everything else lives here.

MarketNow doesn't sell AI tools. It determines whether AI agents should be allowed to trust and execute them.

[npm version] [npm downloads] [License: AliceLabs LLC Proprietary] [Official MCP Registry]

What is MarketNow?

MarketNow is trust infrastructure for AI agents: a hosted registry that verifies skills, credentials and domains across 68,388 indexed MCP servers (132,737 tracked across GitHub, npm and PyPI), with signed skill submissions, revocation checks and a 9-tool MCP API.

Every indexed entry is security-first scored. The MCP API is free — 68,387 of the 68,388 indexed servers are free to install (paid: 1 in the public stats API).

The 9 MCP tools (endpoint v1.15.0)

Endpoint tracks the npm train: v1.15.0 (2026-09-26 — repository-field repair → alicelabs-llc/MARKETNOW, npm ↔ endpoint lockstep); previously v1.14.1 (2026-09-20).

The MCP server exposes 9 tools, all under the marketnow_* namespace so Claude Desktop, Cursor, Cline, LangChain and LlamaIndex can disambiguate them at tool-choice time:

#ToolWhat it does
1marketnow_verify_trustVerify any AI-agent credential (JWT, W3C VC, MCP Card, ATC v3, A2A, EAT-AI, ZTA, X.509) through the UTA 12-stage verification pipeline
2marketnow_translate_credentialTranslate a credential between 8 formats (ATC v3, JWT, W3C VC, A2A, EAT-AI, ZTA, MCP Card, X.509) losslessly via the Universal Trust Schema
3marketnow_list_formatsList the 8 supported credential formats with their algorithms and status
4marketnow_get_pipelineGet the 12-stage verification pipeline details
5marketnow_check_domainScam checker: returns a domain risk score with reasons
6marketnow_search_skillsSearch the registry of indexed MCP servers (GitHub, npm, PyPI), security-first scored
7marketnow_check_revocationCheck revocation of an Agent Trust Card or CA key against the signed Revocation Registry (MNR-CRL-1.0) + live ledger
8marketnow_fingerprint_toolCryptographically fingerprint MCP tool definitions (OWASP MCP Cheat Sheet) with RFC 8785 JCS + SHA-256
9marketnow_submit_skillPublish a skill to the catalog: validated and Sentinel-scanned (injection patterns, embedded secrets, dangerous capabilities)

Tool contract: deterministic marketnow_ snake_case names · intent-oriented descriptions · strict JSON-Schema parameters · structured { content, isError } responses.

Quick start

Connect any MCP client (Streamable HTTP)

json
{  "mcpServers": {    "marketnow": {      "url": "https://www.marketnow.site/api/mcp"    }  }}

Run the MCP server

bash
npx -y marketnow-mcp

Run it in Docker (audited repo tree, published by CI)

bash
docker run -i --rm ghcr.io/alicelabs-llc/marketnow-mcp:1.15.0# or register it in the Docker MCP Toolkit:docker mcp gateway add --docker ghcr.io/alicelabs-llc/marketnow-mcp

Cline

Paste the ready block from integrations/cline/cline_mcp_settings.json into Cline → MCP Servers → Configure. The repo also ships .clinerules/ house rules. Guide: integrations/cline/README.md.

Cursor

Open this repo as your Cursor workspace — .cursor/mcp.json auto-registers the server, and .cursor/rules/marketnow.mdc teaches Cursor the house rules. Guide: integrations/cursor/README.md.

Verify an Agent Trust Card (ATC/1.3)

bash
curl "https://www.marketnow.site/api/atc?action=ca-key"    # public CA key (Ed25519, RFC 8032)curl "https://www.marketnow.site/api/atc?action=spec"      # ATC/1.3 specificationcurl "https://www.marketnow.site/api/atc?action=verify&card_id=ATC-2026-XXXXX"

Stats (public, machine-readable)

MetricValue
MCP servers indexed68,388
Tracked across all sources132,737
Core certified (L1)59,946
Community indexed9,131
Free to install68,387 of 68,388 (paid: 1)
Paid1
L1 index checks10/10 passing
L2 Sentinel scans2,839 of 2,868 npm tarballs
Credential formats8 (ATC v3, JWT, W3C VC, A2A, EAT-AI, ZTA, MCP Card, X.509)
Verification pipeline12 stages (UTA)
CAEd25519 (RFC 8032)

Source of truth: https://www.marketnow.site/api/stats.json — CI fails if any surface diverges.

Security model

Two levels:

  • L1 — index certification: all 68,388 entries pass 10 metadata/security checks before being indexed.
  • L2 — Sentinel scans: shipped npm tarballs are scanned (2,839 to date) for injection patterns, embedded secrets and dangerous capabilities. Skills that fail are quarantined and published in the transparency report.

Conformance

Canonical conformance vectors for the UTA pipeline: /uta/conformance/vectors/_index.json (schema 1.5.0).

Links

License

All code in this repository is PROPRIETARY — property of AliceLabs LLC.

For licensing: [email protected] For support: [email protected] General: [email protected]

Built by AliceLabs LLC (Wyoming, USA) — founder Edison Flores.

来源:README.md,提交 8e2e146

工具

0
工具元数据尚未被收录。

版本历史

1
  1. v1.15.0最新Sep 29, 2026