MarketNow

io.github.alicelabs-llcv1.15.0更新於 Sep 29, 2026

Verify AI agent credentials, translate 9 formats, check scam domains, search 68k+ MCP servers.

已驗證Streamable HTTP可網頁執行Developer ToolsSecurity & MonitoringWeb Search & Scraping

概覽

AI 產生的概覽

讓助理驗證 AI 代理憑證、在多種格式間轉換憑證、檢查網域詐騙風險,並搜尋已索引的 MCP 伺服器登錄庫。

功能
提供九個 marketnow_* 工具:透過 12 階段流程驗證 JWT、W3C VC、MCP Card、ATC v3、A2A、EAT-AI、ZTA、X.509 等代理憑證(R20),在八種格式間無損轉換憑證(R21),列出支援的格式與流程階段(R22、R23),給出網域詐騙風險評分(R24),搜尋已索引的 MCP 伺服器登錄庫(R25),對照簽章撤銷登錄庫檢查撤銷狀態(R26),以 JCS 與 SHA-256 對 MCP 工具定義做指紋(R27),並在驗證與掃描後提交技能到目錄(R28)。
適用情境
當助理需要在執行前判斷某個 AI 代理、憑證或網域是否可信時適用,也適合查找與比較已索引的 MCP 伺服器。需要憑證格式轉換、撤銷檢查或工具定義指紋的工作流程同樣適用。它不是通用工具伺服器。
執行需求
可作為遠端 Streamable HTTP 端點連線(R31),也可透過 npx marketnow-mcp(R32)或已發佈的 Docker 映像(R33)在本機執行。npm 套件需要 Node.js,Docker 方式需要容器執行環境。清單未宣告驗證、環境變數或標頭。託管工具需要能連線到廠商端點。
安裝前請注意
submit 工具會把技能發佈到公開目錄,發佈前會做驗證與掃描(R28),因此應視為公開提交。驗證、轉換、網域檢查與撤銷檢查會把所提供的憑證、網域或卡片識別碼傳送到託管端點。清單未宣告任何憑證或 API 金鑰,但不要把機密或私鑰貼進工具輸入。

安裝

在 SourceWeft 中

  1. 開啟 儀表板中的 MarketNow,將其新增到工作區。
  2. 為需要使用其工具的對話啟用該服務。

Web executable,透過 Streamable HTTP。 遠端服務在工作區中設定後即可從網頁執行環境執行。

其他 MCP 客戶端

把它新增到你客戶端的 mcpServers 設定中。

{
  "mcpServers": {
    "marketnow": {
      "type": "http",
      "url": "https://marketnow.site/api/mcp/"
    }
  }
}

README

MarketNow — Trust Infrastructure for AI Agents

Repo ecosystem (one owner per concern, split 2026-09-26):

RepoSole owner of
alicelabs-llc/MARKETNOW (this repo)Product code: mcp-server (npm marketnow-mcp), atc-sdk/atc-python/atc-rust, Docker/Cline/Cursor integrations, CLIs, security audits
eddyflores100-lang/marketnowLive marketplace: site (aep-marketplace/), catalog data (_data/, skills/, public/api/), the 21 scheduled data pipelines, Vercel deploys of marketnow.site
alicelabs-llc/universal-trust-adapterATC/1.0 protocol: spec, adapters, reference implementation, plugins
alicelabs-llc/marketnow-submissionsPublic skill submissions queue
alicelabs-llc/statusLive status page

Data and site questions go to the marketplace repo; protocol questions to UTA; everything else lives here.

MarketNow doesn't sell AI tools. It determines whether AI agents should be allowed to trust and execute them.

[npm version] [npm downloads] [License: AliceLabs LLC Proprietary] [Official MCP Registry]

What is MarketNow?

MarketNow is trust infrastructure for AI agents: a hosted registry that verifies skills, credentials and domains across 68,388 indexed MCP servers (132,737 tracked across GitHub, npm and PyPI), with signed skill submissions, revocation checks and a 9-tool MCP API.

Every indexed entry is security-first scored. The MCP API is free — 68,387 of the 68,388 indexed servers are free to install (paid: 1 in the public stats API).

The 9 MCP tools (endpoint v1.15.0)

Endpoint tracks the npm train: v1.15.0 (2026-09-26 — repository-field repair → alicelabs-llc/MARKETNOW, npm ↔ endpoint lockstep); previously v1.14.1 (2026-09-20).

The MCP server exposes 9 tools, all under the marketnow_* namespace so Claude Desktop, Cursor, Cline, LangChain and LlamaIndex can disambiguate them at tool-choice time:

#ToolWhat it does
1marketnow_verify_trustVerify any AI-agent credential (JWT, W3C VC, MCP Card, ATC v3, A2A, EAT-AI, ZTA, X.509) through the UTA 12-stage verification pipeline
2marketnow_translate_credentialTranslate a credential between 8 formats (ATC v3, JWT, W3C VC, A2A, EAT-AI, ZTA, MCP Card, X.509) losslessly via the Universal Trust Schema
3marketnow_list_formatsList the 8 supported credential formats with their algorithms and status
4marketnow_get_pipelineGet the 12-stage verification pipeline details
5marketnow_check_domainScam checker: returns a domain risk score with reasons
6marketnow_search_skillsSearch the registry of indexed MCP servers (GitHub, npm, PyPI), security-first scored
7marketnow_check_revocationCheck revocation of an Agent Trust Card or CA key against the signed Revocation Registry (MNR-CRL-1.0) + live ledger
8marketnow_fingerprint_toolCryptographically fingerprint MCP tool definitions (OWASP MCP Cheat Sheet) with RFC 8785 JCS + SHA-256
9marketnow_submit_skillPublish a skill to the catalog: validated and Sentinel-scanned (injection patterns, embedded secrets, dangerous capabilities)

Tool contract: deterministic marketnow_ snake_case names · intent-oriented descriptions · strict JSON-Schema parameters · structured { content, isError } responses.

Quick start

Connect any MCP client (Streamable HTTP)

json
{  "mcpServers": {    "marketnow": {      "url": "https://www.marketnow.site/api/mcp"    }  }}

Run the MCP server

bash
npx -y marketnow-mcp

Run it in Docker (audited repo tree, published by CI)

bash
docker run -i --rm ghcr.io/alicelabs-llc/marketnow-mcp:1.15.0# or register it in the Docker MCP Toolkit:docker mcp gateway add --docker ghcr.io/alicelabs-llc/marketnow-mcp

Cline

Paste the ready block from integrations/cline/cline_mcp_settings.json into Cline → MCP Servers → Configure. The repo also ships .clinerules/ house rules. Guide: integrations/cline/README.md.

Cursor

Open this repo as your Cursor workspace — .cursor/mcp.json auto-registers the server, and .cursor/rules/marketnow.mdc teaches Cursor the house rules. Guide: integrations/cursor/README.md.

Verify an Agent Trust Card (ATC/1.3)

bash
curl "https://www.marketnow.site/api/atc?action=ca-key"    # public CA key (Ed25519, RFC 8032)curl "https://www.marketnow.site/api/atc?action=spec"      # ATC/1.3 specificationcurl "https://www.marketnow.site/api/atc?action=verify&card_id=ATC-2026-XXXXX"

Stats (public, machine-readable)

MetricValue
MCP servers indexed68,388
Tracked across all sources132,737
Core certified (L1)59,946
Community indexed9,131
Free to install68,387 of 68,388 (paid: 1)
Paid1
L1 index checks10/10 passing
L2 Sentinel scans2,839 of 2,868 npm tarballs
Credential formats8 (ATC v3, JWT, W3C VC, A2A, EAT-AI, ZTA, MCP Card, X.509)
Verification pipeline12 stages (UTA)
CAEd25519 (RFC 8032)

Source of truth: https://www.marketnow.site/api/stats.json — CI fails if any surface diverges.

Security model

Two levels:

  • L1 — index certification: all 68,388 entries pass 10 metadata/security checks before being indexed.
  • L2 — Sentinel scans: shipped npm tarballs are scanned (2,839 to date) for injection patterns, embedded secrets and dangerous capabilities. Skills that fail are quarantined and published in the transparency report.

Conformance

Canonical conformance vectors for the UTA pipeline: /uta/conformance/vectors/_index.json (schema 1.5.0).

Links

License

All code in this repository is PROPRIETARY — property of AliceLabs LLC.

For licensing: [email protected] For support: [email protected] General: [email protected]

Built by AliceLabs LLC (Wyoming, USA) — founder Edison Flores.

來源:README.md,提交 8e2e146

工具

0
工具後設資料尚未被收錄。

版本歷史

1
  1. v1.15.0最新Sep 29, 2026