MarketNow
Verify AI agent credentials, translate 9 formats, check scam domains, search 68k+ MCP servers.
Should I use this
Quality & Safety
Findings (2)
- HIGH
- MEDIUMin marketnow_check_revocation
Based on automated analysis of tool definitions and protocol compliance.
Context Cost
This is the approximate number of tokens consumed each time the server's tools are loaded into a model's context. Higher counts reduce the attention available for other tasks.
Install
One-Click Install
Add this to your `claude_desktop_config.json` file:
{
"mcpServers": {
"marketnow": {
"command": "npx",
"args": [
"marketnow-mcp"
]
}
}
}Runnable packages
1.15.0stdioRemote endpoints
https://marketnow.site/api/mcp/streamable-httpWhat it can do
Tool inventory
Tools (9)
π’marketnow_verify_trust(credential)
Verify any AI agent credential (ATC v3, JWT/OAuth, W3C VC, MCP Card, A2A, EAT-AI, ZTA, SPIFFE SVID, X.509) through the UTA 12-stage credential-verification pipeline (PARSEβDECISION β distinct from Sentinel's 12 skill-audit stages). Returns validity, format, trust score, and issues.
Input Schema
{
"type": "object",
"properties": {
"credential": {
"type": "string",
"description": "The credential to verify (JSON string or JWT)"
}
},
"required": [
"credential"
]
}π’marketnow_translate_credential(from, to, payload)
Translate a credential between the 9 adapter formats (ATC, JWT/OAuth, W3C VC, A2A, EAT-AI, ZTA, MCP Card, SPIFFE, X.509). Lossless conversion through Universal Trust Schema (UTS). See /api/trust?action=formats.
Input Schema
{
"type": "object",
"properties": {
"from": {
"type": "string",
"description": "Source format: atc-v3, jwt, w3c-vc, a2a-card, mcp-card, x509"
},
"to": {
"type": "string",
"description": "Target format: atc-v3, jwt, w3c-vc, a2a-card, mcp-card, x509"
},
"payload": {
"type": "string",
"description": "The credential JSON to translate"
}
},
"required": [
"from",
"to",
"payload"
]
}π’marketnow_list_formats
List all 9 supported credential adapter formats (ATC, EAT-AI, ZTA, A2A, MCP Card, W3C VC, OAuth, SPIFFE, X.509) with their algorithms and status.
Input Schema
{
"type": "object",
"properties": {}
}π’marketnow_get_pipeline
Get the 12-stage credential-verification pipeline details (PARSEβDECISION).
Input Schema
{
"type": "object",
"properties": {}
}π’marketnow_check_domain(domain)
Check if a domain is suspicious (scam checker). Returns risk score and reasons.
Input Schema
{
"type": "object",
"properties": {
"domain": {
"type": "string",
"description": "The domain to check (e.g. example.com)"
}
},
"required": [
"domain"
]
}π’marketnow_search_skills(query, category)
Search the MarketNow registry of indexed MCP servers (68k+ across GitHub, npm and PyPI, security-first scored).
Input Schema
{
"type": "object",
"properties": {
"query": {
"type": "string",
"description": "Search query"
},
"category": {
"type": "string",
"description": "Filter by category"
}
}
}π’marketnow_check_revocation(card_id, kid, nonce)
Check the revocation status of an Agent Trust Card (card_id) or CA key (kid) against the signed MarketNow Revocation Registry (MNR-CRL-1.0) + live ledger. Returns VALID/EXPIRED/REVOKED/SUPERSEDED/UNKNOWN with PERMIT/DENY recommendation. Fail-closed: unknown subjects answer UNKNOWN+DENY. The signed CRL layer is independently verifiable via Ed25519 (RFC 8785 JCS).
Input Schema
{
"type": "object",
"properties": {
"card_id": {
"type": "string",
"description": "Agent Trust Card ID (e.g. ATC-2026-1509360)"
},
"kid": {
"type": "string",
"description": "CA key ID (e.g. mn-ca-002, mn-ca-003)"
},
"nonce": {
"type": "string",
"description": "Optional client nonce β echoed in the response (anti-replay)"
}
}
}π’marketnow_fingerprint_tool(tools, pinned)
Cryptographically fingerprint MCP tool definitions (OWASP MCP Cheat Sheet: 'verify tool descriptions haven't changed'). Computes RFC 8785 JCS + sha256 per tool plus a manifest fingerprint for the whole tools/list surface. Pass a previous manifest in 'pinned' to get a drift report (added/removed/changed) β the core defense against tool poisoning and rug-pull redefinitions.
Input Schema
{
"type": "object",
"properties": {
"tools": {
"type": "array",
"description": "Tool definitions from tools/list: [{name, description, inputSchema}]",
"items": {
"type": "object"
}
},
"pinned": {
"type": "object",
"description": "Optional: previous manifest {tools:[{name, fingerprint_sha256}]} from an earlier fingerprint run β enables drift detection"
}
},
"required": [
"tools"
]
}π‘marketnow_submit_skill(skill, dry_run)
Publish a skill to the MarketNow catalog (the write side). The package is validated and Sentinel-scanned (injection patterns, embedded secrets, dangerous APIs, suspicious URLs, typosquat, dedup against the 68k+ catalog) AND its claims are verified live: repo_url must exist (HTTP 200), install must reference a real package on npm/PyPI/crates/Docker Hub. False claims are rejected (422). Accepted skills with real substance (files/code/verifiable repo) are stored in the public auditable queue as certified-L1.5, pending L2 review and catalog merge. Description-only submissions are accepted but never merged. Any pricing model is accepted β free, per-call (x402), subscription or custom: the vendor sets the price, MarketNow verifies the security. No authentication required. Do NOT include secrets β the scanner rejects them.
Input Schema
{
"type": "object",
"properties": {
"skill": {
"type": "object",
"description": "Skill package. Required: name, version, description, author. Recommended: runtime (node|python|rust|go|dotnet|docker|luau|roblox|other), install, repo_url, homepage, tags (max 12), capabilities, doc.usage, doc.system_prompt, files {name:content} (max 60KB), test.url (https β probed), pricing {model: free|per-call|per-call-x402|subscription|one-time|freemium|revenue-share|custom, price, currency, details max 300} β the vendor sets any price; we verify security, not pricing."
},
"dry_run": {
"type": "boolean",
"description": "If true, run the full validation + scan but store nothing"
}
},
"required": [
"skill"
]
}Community
Evidence