Back to Browse

MARKETNOW MCP Server

Developer ToolsUse Caution4.2MCP RegistryLocalRemote
Free

Server data from the Official MCP Registry

Verify AI agent credentials, translate 9 formats, check scam domains, search 68k+ MCP servers.

About

Verify AI agent credentials, translate 9 formats, check scam domains, search 68k+ MCP servers.

Remote endpoints: streamable-http: https://marketnow.site/api/mcp/

Security Report

4.2
Use Caution4.2High Risk

MarketNow MCP server is a well-architected trust infrastructure service with strong input validation, proper error handling, and clear security boundaries. However, there are moderate concerns around unencrypted HTTP credential transmission, network dependency for core operations, and some edge cases in error handling that prevent a higher score. The codebase demonstrates mature security practices (fail-closed verification, Zod validation, revocation checks) but lacks some hardening in transport security. Supply chain analysis found 9 known vulnerabilities in dependencies (0 critical, 3 high severity). Package verification found 1 issue (1 critical, 0 high severity).

4 files analyzed · 17 issues found

Security scores are indicators to help you make informed decisions, not guarantees. Always review permissions before connecting any MCP server.

Permissions Required

This plugin requests these system permissions. Most are normal for its category.

HTTP Network Access

Connects to external APIs or services over the internet.

env_vars

Check that this permission is expected for this type of plugin.

Unverified package source

We couldn't verify that the installable package matches the reviewed source code. Proceed with caution.

How to Install & Connect

Available as Local & Remote

This plugin can run on your machine or connect to a hosted endpoint. during install.

Documentation

View on GitHub

From the project's GitHub README.

MarketNow — Trust Infrastructure for AI Agents

Repo ecosystem (one owner per concern, split 2026-09-26):

RepoSole owner of
alicelabs-llc/MARKETNOW (this repo)Product code: mcp-server (npm marketnow-mcp), atc-sdk/atc-python/atc-rust, Docker/Cline/Cursor integrations, CLIs, security audits
eddyflores100-lang/marketnowLive marketplace: site (aep-marketplace/), catalog data (_data/, skills/, public/api/), the 21 scheduled data pipelines, Vercel deploys of marketnow.site
alicelabs-llc/universal-trust-adapterATC/1.0 protocol: spec, adapters, reference implementation, plugins
alicelabs-llc/marketnow-submissionsPublic skill submissions queue
alicelabs-llc/statusLive status page

Data and site questions go to the marketplace repo; protocol questions to UTA; everything else lives here.

MarketNow doesn't sell AI tools. It determines whether AI agents should be allowed to trust and execute them.

npm version npm downloads License: AliceLabs LLC Proprietary Official MCP Registry

What is MarketNow?

MarketNow is trust infrastructure for AI agents: a hosted registry that verifies skills, credentials and domains across 68,388 indexed MCP servers (132,737 tracked across GitHub, npm and PyPI), with signed skill submissions, revocation checks and a 9-tool MCP API.

Every indexed entry is security-first scored. The MCP API is free — 68,387 of the 68,388 indexed servers are free to install (paid: 1 in the public stats API).

The 9 MCP tools (endpoint v1.15.0)

Endpoint tracks the npm train: v1.15.0 (2026-09-26 — repository-field repair → alicelabs-llc/MARKETNOW, npm ↔ endpoint lockstep); previously v1.14.1 (2026-09-20).

The MCP server exposes 9 tools, all under the marketnow_* namespace so Claude Desktop, Cursor, Cline, LangChain and LlamaIndex can disambiguate them at tool-choice time:

#ToolWhat it does
1marketnow_verify_trustVerify any AI-agent credential (JWT, W3C VC, MCP Card, ATC v3, A2A, EAT-AI, ZTA, X.509) through the UTA 12-stage verification pipeline
2marketnow_translate_credentialTranslate a credential between 8 formats (ATC v3, JWT, W3C VC, A2A, EAT-AI, ZTA, MCP Card, X.509) losslessly via the Universal Trust Schema
3marketnow_list_formatsList the 8 supported credential formats with their algorithms and status
4marketnow_get_pipelineGet the 12-stage verification pipeline details
5marketnow_check_domainScam checker: returns a domain risk score with reasons
6marketnow_search_skillsSearch the registry of indexed MCP servers (GitHub, npm, PyPI), security-first scored
7marketnow_check_revocationCheck revocation of an Agent Trust Card or CA key against the signed Revocation Registry (MNR-CRL-1.0) + live ledger
8marketnow_fingerprint_toolCryptographically fingerprint MCP tool definitions (OWASP MCP Cheat Sheet) with RFC 8785 JCS + SHA-256
9marketnow_submit_skillPublish a skill to the catalog: validated and Sentinel-scanned (injection patterns, embedded secrets, dangerous capabilities)

Tool contract: deterministic marketnow_ snake_case names · intent-oriented descriptions · strict JSON-Schema parameters · structured { content, isError } responses.

Quick start

Add to Cursor — 1 click (no terminal)

Add to Cursor

Connect any MCP client (Streamable HTTP)

{
  "mcpServers": {
    "marketnow": {
      "url": "https://www.marketnow.site/api/mcp"
    }
  }
}

Run the MCP server

npx -y marketnow-mcp

Run it in Docker (audited repo tree, published by CI)

docker run -i --rm ghcr.io/alicelabs-llc/marketnow-mcp:1.15.0
# or register it in the Docker MCP Toolkit:
docker mcp gateway add --docker ghcr.io/alicelabs-llc/marketnow-mcp

Cline

Paste the ready block from integrations/cline/cline_mcp_settings.json into Cline → MCP Servers → Configure. The repo also ships .clinerules/ house rules. Guide: integrations/cline/README.md.

Cursor

Open this repo as your Cursor workspace — .cursor/mcp.json auto-registers the server, and .cursor/rules/marketnow.mdc teaches Cursor the house rules. Guide: integrations/cursor/README.md.

Verify an Agent Trust Card (ATC/1.3)

curl "https://www.marketnow.site/api/atc?action=ca-key"    # public CA key (Ed25519, RFC 8032)
curl "https://www.marketnow.site/api/atc?action=spec"      # ATC/1.3 specification
curl "https://www.marketnow.site/api/atc?action=verify&card_id=ATC-2026-XXXXX"

Stats (public, machine-readable)

MetricValue
MCP servers indexed68,388
Tracked across all sources132,737
Core certified (L1)59,946
Community indexed9,131
Free to install68,387 of 68,388 (paid: 1)
Paid1
L1 index checks10/10 passing
L2 Sentinel scans2,839 of 2,868 npm tarballs
Credential formats8 (ATC v3, JWT, W3C VC, A2A, EAT-AI, ZTA, MCP Card, X.509)
Verification pipeline12 stages (UTA)
CAEd25519 (RFC 8032)

Source of truth: https://www.marketnow.site/api/stats.json — CI fails if any surface diverges.

Security model

Two levels:

  • L1 — index certification: all 68,388 entries pass 10 metadata/security checks before being indexed.
  • L2 — Sentinel scans: shipped npm tarballs are scanned (2,839 to date) for injection patterns, embedded secrets and dangerous capabilities. Skills that fail are quarantined and published in the transparency report.

Conformance

Canonical conformance vectors for the UTA pipeline: /uta/conformance/vectors/_index.json (schema 1.5.0).

Links

License

All code in this repository is PROPRIETARY — property of AliceLabs LLC.

For licensing: legal@alicelabs.site For support: support@alicelabs.site General: info@alicelabs.site

Built by AliceLabs LLC (Wyoming, USA) — founder Edison Flores.

Reviews

No reviews yet

Be the first to review this server!