MarketNow
Verify AI agent credentials, translate 9 formats, check scam domains, search 68k+ MCP servers.
Sollte ich dies verwenden
Qualität und Sicherheit
Befunde (2)
- HIGH
- MEDIUMin marketnow_check_revocation
Basierend auf einer automatisierten Analyse der Tool-Definitionen und der Einhaltung des Protokolls.
Kontextkosten
Dies ist die ungefähre Anzahl der Tokens, die jedes Mal verbraucht werden, wenn die Tools des Servers in den Kontext eines Modells geladen werden. Höhere Werte verringern die Aufmerksamkeit, die für andere Aufgaben verfügbar ist.
Installieren
Installation mit einem Klick
Fügen Sie dies Ihrer Datei `claude_desktop_config.json` hinzu:
{
"mcpServers": {
"marketnow": {
"command": "npx",
"args": [
"marketnow-mcp"
]
}
}
}Ausführbare Pakete
1.15.0stdioRemote-Endpunkte
https://marketnow.site/api/mcp/streamable-httpWas es kann
Tool-Inventar
Tools (9)
🟢marketnow_verify_trust(credential)
Verify any AI agent credential (ATC v3, JWT/OAuth, W3C VC, MCP Card, A2A, EAT-AI, ZTA, SPIFFE SVID, X.509) through the UTA 12-stage credential-verification pipeline (PARSE→DECISION — distinct from Sentinel's 12 skill-audit stages). Returns validity, format, trust score, and issues.
Eingabe-Schema
{
"type": "object",
"properties": {
"credential": {
"type": "string",
"description": "The credential to verify (JSON string or JWT)"
}
},
"required": [
"credential"
]
}🟢marketnow_translate_credential(from, to, payload)
Translate a credential between the 9 adapter formats (ATC, JWT/OAuth, W3C VC, A2A, EAT-AI, ZTA, MCP Card, SPIFFE, X.509). Lossless conversion through Universal Trust Schema (UTS). See /api/trust?action=formats.
Eingabe-Schema
{
"type": "object",
"properties": {
"from": {
"type": "string",
"description": "Source format: atc-v3, jwt, w3c-vc, a2a-card, mcp-card, x509"
},
"to": {
"type": "string",
"description": "Target format: atc-v3, jwt, w3c-vc, a2a-card, mcp-card, x509"
},
"payload": {
"type": "string",
"description": "The credential JSON to translate"
}
},
"required": [
"from",
"to",
"payload"
]
}🟢marketnow_list_formats
List all 9 supported credential adapter formats (ATC, EAT-AI, ZTA, A2A, MCP Card, W3C VC, OAuth, SPIFFE, X.509) with their algorithms and status.
Eingabe-Schema
{
"type": "object",
"properties": {}
}🟢marketnow_get_pipeline
Get the 12-stage credential-verification pipeline details (PARSE→DECISION).
Eingabe-Schema
{
"type": "object",
"properties": {}
}🟢marketnow_check_domain(domain)
Check if a domain is suspicious (scam checker). Returns risk score and reasons.
Eingabe-Schema
{
"type": "object",
"properties": {
"domain": {
"type": "string",
"description": "The domain to check (e.g. example.com)"
}
},
"required": [
"domain"
]
}🟢marketnow_search_skills(query, category)
Search the MarketNow registry of indexed MCP servers (68k+ across GitHub, npm and PyPI, security-first scored).
Eingabe-Schema
{
"type": "object",
"properties": {
"query": {
"type": "string",
"description": "Search query"
},
"category": {
"type": "string",
"description": "Filter by category"
}
}
}🟢marketnow_check_revocation(card_id, kid, nonce)
Check the revocation status of an Agent Trust Card (card_id) or CA key (kid) against the signed MarketNow Revocation Registry (MNR-CRL-1.0) + live ledger. Returns VALID/EXPIRED/REVOKED/SUPERSEDED/UNKNOWN with PERMIT/DENY recommendation. Fail-closed: unknown subjects answer UNKNOWN+DENY. The signed CRL layer is independently verifiable via Ed25519 (RFC 8785 JCS).
Eingabe-Schema
{
"type": "object",
"properties": {
"card_id": {
"type": "string",
"description": "Agent Trust Card ID (e.g. ATC-2026-1509360)"
},
"kid": {
"type": "string",
"description": "CA key ID (e.g. mn-ca-002, mn-ca-003)"
},
"nonce": {
"type": "string",
"description": "Optional client nonce — echoed in the response (anti-replay)"
}
}
}🟢marketnow_fingerprint_tool(tools, pinned)
Cryptographically fingerprint MCP tool definitions (OWASP MCP Cheat Sheet: 'verify tool descriptions haven't changed'). Computes RFC 8785 JCS + sha256 per tool plus a manifest fingerprint for the whole tools/list surface. Pass a previous manifest in 'pinned' to get a drift report (added/removed/changed) — the core defense against tool poisoning and rug-pull redefinitions.
Eingabe-Schema
{
"type": "object",
"properties": {
"tools": {
"type": "array",
"description": "Tool definitions from tools/list: [{name, description, inputSchema}]",
"items": {
"type": "object"
}
},
"pinned": {
"type": "object",
"description": "Optional: previous manifest {tools:[{name, fingerprint_sha256}]} from an earlier fingerprint run — enables drift detection"
}
},
"required": [
"tools"
]
}🟡marketnow_submit_skill(skill, dry_run)
Publish a skill to the MarketNow catalog (the write side). The package is validated and Sentinel-scanned (injection patterns, embedded secrets, dangerous APIs, suspicious URLs, typosquat, dedup against the 68k+ catalog) AND its claims are verified live: repo_url must exist (HTTP 200), install must reference a real package on npm/PyPI/crates/Docker Hub. False claims are rejected (422). Accepted skills with real substance (files/code/verifiable repo) are stored in the public auditable queue as certified-L1.5, pending L2 review and catalog merge. Description-only submissions are accepted but never merged. Any pricing model is accepted — free, per-call (x402), subscription or custom: the vendor sets the price, MarketNow verifies the security. No authentication required. Do NOT include secrets — the scanner rejects them.
Eingabe-Schema
{
"type": "object",
"properties": {
"skill": {
"type": "object",
"description": "Skill package. Required: name, version, description, author. Recommended: runtime (node|python|rust|go|dotnet|docker|luau|roblox|other), install, repo_url, homepage, tags (max 12), capabilities, doc.usage, doc.system_prompt, files {name:content} (max 60KB), test.url (https — probed), pricing {model: free|per-call|per-call-x402|subscription|one-time|freemium|revenue-share|custom, price, currency, details max 300} — the vendor sets any price; we verify security, not pricing."
},
"dry_run": {
"type": "boolean",
"description": "If true, run the full validation + scan but store nothing"
}
},
"required": [
"skill"
]
}Community
Nachweis