MarketNow
Verify AI agent credentials, translate 9 formats, check scam domains, search 68k+ MCP servers.
¿Debería usar esto?
Calidad y seguridad
Hallazgos (2)
- HIGH
- MEDIUMen marketnow_check_revocation
Basado en el análisis automatizado de las definiciones de herramientas y el cumplimiento del protocolo.
Costo de contexto
Este es el número aproximado de tokens que se consumen cada vez que las herramientas del servidor se cargan en el contexto de un modelo. Los recuentos más altos reducen la atención disponible para otras tareas.
Instalar
Instalación con un clic
Agrega esto a tu archivo `claude_desktop_config.json`:
{
"mcpServers": {
"marketnow": {
"command": "npx",
"args": [
"marketnow-mcp"
]
}
}
}Paquetes ejecutables
1.15.0stdioPuntos de conexión remotos
https://marketnow.site/api/mcp/streamable-httpQué puede hacer
Inventario de herramientas
Herramientas (9)
🟢marketnow_verify_trust(credential)
Verify any AI agent credential (ATC v3, JWT/OAuth, W3C VC, MCP Card, A2A, EAT-AI, ZTA, SPIFFE SVID, X.509) through the UTA 12-stage credential-verification pipeline (PARSE→DECISION — distinct from Sentinel's 12 skill-audit stages). Returns validity, format, trust score, and issues.
Esquema de entrada
{
"type": "object",
"properties": {
"credential": {
"type": "string",
"description": "The credential to verify (JSON string or JWT)"
}
},
"required": [
"credential"
]
}🟢marketnow_translate_credential(from, to, payload)
Translate a credential between the 9 adapter formats (ATC, JWT/OAuth, W3C VC, A2A, EAT-AI, ZTA, MCP Card, SPIFFE, X.509). Lossless conversion through Universal Trust Schema (UTS). See /api/trust?action=formats.
Esquema de entrada
{
"type": "object",
"properties": {
"from": {
"type": "string",
"description": "Source format: atc-v3, jwt, w3c-vc, a2a-card, mcp-card, x509"
},
"to": {
"type": "string",
"description": "Target format: atc-v3, jwt, w3c-vc, a2a-card, mcp-card, x509"
},
"payload": {
"type": "string",
"description": "The credential JSON to translate"
}
},
"required": [
"from",
"to",
"payload"
]
}🟢marketnow_list_formats
List all 9 supported credential adapter formats (ATC, EAT-AI, ZTA, A2A, MCP Card, W3C VC, OAuth, SPIFFE, X.509) with their algorithms and status.
Esquema de entrada
{
"type": "object",
"properties": {}
}🟢marketnow_get_pipeline
Get the 12-stage credential-verification pipeline details (PARSE→DECISION).
Esquema de entrada
{
"type": "object",
"properties": {}
}🟢marketnow_check_domain(domain)
Check if a domain is suspicious (scam checker). Returns risk score and reasons.
Esquema de entrada
{
"type": "object",
"properties": {
"domain": {
"type": "string",
"description": "The domain to check (e.g. example.com)"
}
},
"required": [
"domain"
]
}🟢marketnow_search_skills(query, category)
Search the MarketNow registry of indexed MCP servers (68k+ across GitHub, npm and PyPI, security-first scored).
Esquema de entrada
{
"type": "object",
"properties": {
"query": {
"type": "string",
"description": "Search query"
},
"category": {
"type": "string",
"description": "Filter by category"
}
}
}🟢marketnow_check_revocation(card_id, kid, nonce)
Check the revocation status of an Agent Trust Card (card_id) or CA key (kid) against the signed MarketNow Revocation Registry (MNR-CRL-1.0) + live ledger. Returns VALID/EXPIRED/REVOKED/SUPERSEDED/UNKNOWN with PERMIT/DENY recommendation. Fail-closed: unknown subjects answer UNKNOWN+DENY. The signed CRL layer is independently verifiable via Ed25519 (RFC 8785 JCS).
Esquema de entrada
{
"type": "object",
"properties": {
"card_id": {
"type": "string",
"description": "Agent Trust Card ID (e.g. ATC-2026-1509360)"
},
"kid": {
"type": "string",
"description": "CA key ID (e.g. mn-ca-002, mn-ca-003)"
},
"nonce": {
"type": "string",
"description": "Optional client nonce — echoed in the response (anti-replay)"
}
}
}🟢marketnow_fingerprint_tool(tools, pinned)
Cryptographically fingerprint MCP tool definitions (OWASP MCP Cheat Sheet: 'verify tool descriptions haven't changed'). Computes RFC 8785 JCS + sha256 per tool plus a manifest fingerprint for the whole tools/list surface. Pass a previous manifest in 'pinned' to get a drift report (added/removed/changed) — the core defense against tool poisoning and rug-pull redefinitions.
Esquema de entrada
{
"type": "object",
"properties": {
"tools": {
"type": "array",
"description": "Tool definitions from tools/list: [{name, description, inputSchema}]",
"items": {
"type": "object"
}
},
"pinned": {
"type": "object",
"description": "Optional: previous manifest {tools:[{name, fingerprint_sha256}]} from an earlier fingerprint run — enables drift detection"
}
},
"required": [
"tools"
]
}🟡marketnow_submit_skill(skill, dry_run)
Publish a skill to the MarketNow catalog (the write side). The package is validated and Sentinel-scanned (injection patterns, embedded secrets, dangerous APIs, suspicious URLs, typosquat, dedup against the 68k+ catalog) AND its claims are verified live: repo_url must exist (HTTP 200), install must reference a real package on npm/PyPI/crates/Docker Hub. False claims are rejected (422). Accepted skills with real substance (files/code/verifiable repo) are stored in the public auditable queue as certified-L1.5, pending L2 review and catalog merge. Description-only submissions are accepted but never merged. Any pricing model is accepted — free, per-call (x402), subscription or custom: the vendor sets the price, MarketNow verifies the security. No authentication required. Do NOT include secrets — the scanner rejects them.
Esquema de entrada
{
"type": "object",
"properties": {
"skill": {
"type": "object",
"description": "Skill package. Required: name, version, description, author. Recommended: runtime (node|python|rust|go|dotnet|docker|luau|roblox|other), install, repo_url, homepage, tags (max 12), capabilities, doc.usage, doc.system_prompt, files {name:content} (max 60KB), test.url (https — probed), pricing {model: free|per-call|per-call-x402|subscription|one-time|freemium|revenue-share|custom, price, currency, details max 300} — the vendor sets any price; we verify security, not pricing."
},
"dry_run": {
"type": "boolean",
"description": "If true, run the full validation + scan but store nothing"
}
},
"required": [
"skill"
]
}Comunidad
Evidencia