Serveur MCP

MarketNow

io.github.alicelabs-llc/marketnow
Infrastructure MCP et agents Sécurité Public et accessible MCP 2026-07-28

Ce que fait ce MCP

Verifies agent credentials, translates credential formats, checks domain risks, fingerprints MCP tool definitions, and searches or audits an MCP skill registry.

marketnow_check_domain
Check domain risk
Check if a domain is suspicious (scam checker). Returns risk score and reasons.
Lecture seule Accès externe Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['domain'], 'properties': {'domain': {'type': 'string', 'description': 'The domain to check (e.g. example.com)'}}}
marketnow_check_revocation
Check revocation status
Check the revocation status of an Agent Trust Card (card_id) or CA key (kid) against the signed MarketNow Revocation Registry (MNR-CRL-1.0) + live ledger. Returns VALID/EXPIRED/REVOKED/SUPERSEDED/UNKNOWN with PERMIT/DENY recommendation. Fail-closed: unknown subjects answer UNKNOWN+DENY. The signed CRL layer is independently verifiable via Ed25519 (RFC 8785 JCS).
Lecture seule Idempotent
Schéma d’entrée
{'type': 'object', 'properties': {'kid': {'type': 'string', 'description': 'CA key ID (e.g. mn-ca-002, mn-ca-003)'}, 'nonce': {'type': 'string', 'description': 'Optional client nonce — echoed in the response (anti-replay)'}, 'card_id': {'type': 'string', 'description': 'Agent Trust Card ID (e.g. ATC-2026-1509360)'}}}
marketnow_fingerprint_tool
Fingerprint MCP tools
Cryptographically fingerprint MCP tool definitions (OWASP MCP Cheat Sheet: 'verify tool descriptions haven't changed'). Computes RFC 8785 JCS + sha256 per tool plus a manifest fingerprint for the whole tools/list surface. Pass a previous manifest in 'pinned' to get a drift report (added/removed/changed) — the core defense against tool poisoning and rug-pull redefinitions.
Lecture seule Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['tools'], 'properties': {'tools': {'type': 'array', 'items': {'type': 'object'}, 'description': 'Tool definitions from tools/list: [{name, description, inputSchema}]'}, 'pinned': {'type': 'object', 'description': 'Optional: previous manifest {tools:[{name, fingerprint_sha256}]} from an earlier fingerprint run — enables drift detection'}}}
marketnow_get_pipeline
Get verification pipeline
Get the 12-stage credential-verification pipeline details (PARSE→DECISION).
Lecture seule Idempotent
Schéma d’entrée
{'type': 'object', 'properties': {}}
marketnow_list_formats
List credential formats
List all 9 supported credential adapter formats (ATC, EAT-AI, ZTA, A2A, MCP Card, W3C VC, OAuth, SPIFFE, X.509) with their algorithms and status.
Lecture seule Idempotent
Schéma d’entrée
{'type': 'object', 'properties': {}}
marketnow_search_skills
Search MCP servers
Search the MarketNow registry of indexed MCP servers (68k+ across GitHub, npm and PyPI, security-first scored).
Lecture seule Idempotent
Schéma d’entrée
{'type': 'object', 'properties': {'query': {'type': 'string', 'description': 'Search query'}, 'category': {'type': 'string', 'description': 'Filter by category'}}}
marketnow_submit_skill
Submit MCP skill
Publish a skill to the MarketNow catalog (the write side). The package is validated and Sentinel-scanned (injection patterns, embedded secrets, dangerous APIs, suspicious URLs, typosquat, dedup against the 68k+ catalog) AND its claims are verified live: repo_url must exist (HTTP 200), install must reference a real package on npm/PyPI/crates/Docker Hub. False claims are rejected (422). Accepted skills with real substance (files/code/verifiable repo) are stored in the public auditable queue as certified-L1.5, pending L2 review and catalog merge. Description-only submissions are accepted but never merged. Any pricing model is accepted — free, per-call (x402), subscription or custom: the vendor sets the price, MarketNow verifies the security. No authentication required. Do NOT include secrets — the scanner rejects them.
Accès externe
Schéma d’entrée
{'type': 'object', 'required': ['skill'], 'properties': {'skill': {'type': 'object', 'description': 'Skill package. Required: name, version, description, author. Recommended: runtime (node|python|rust|go|dotnet|docker|luau|roblox|other), install, repo_url, homepage, tags (max 12), capabilities, doc.usage, doc.system_prompt, files {name:content} (max 60KB), test.url (https — probed), pricing {model: free|per-call|per-call-x402|subscription|one-time|freemium|revenue-share|custom, price, currency, details max 300} — the vendor sets any price; we verify security, not pricing.'}, 'dry_run': {'type': 'boolean', 'description': 'If true, run the full validation + scan but store nothing'}}}
marketnow_translate_credential
Translate credential format
Translate a credential between the 9 adapter formats (ATC, JWT/OAuth, W3C VC, A2A, EAT-AI, ZTA, MCP Card, SPIFFE, X.509). Lossless conversion through Universal Trust Schema (UTS). See /api/trust?action=formats.
Lecture seule Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['from', 'to', 'payload'], 'properties': {'to': {'type': 'string', 'description': 'Target format: atc-v3, jwt, w3c-vc, a2a-card, mcp-card, x509'}, 'from': {'type': 'string', 'description': 'Source format: atc-v3, jwt, w3c-vc, a2a-card, mcp-card, x509'}, 'payload': {'type': 'string', 'description': 'The credential JSON to translate'}}}
marketnow_verify_trust
Verify agent credential
Verify any AI agent credential (ATC v3, JWT/OAuth, W3C VC, MCP Card, A2A, EAT-AI, ZTA, SPIFFE SVID, X.509) through the UTA 12-stage credential-verification pipeline (PARSE→DECISION — distinct from Sentinel's 12 skill-audit stages). Returns validity, format, trust score, and issues.
Lecture seule Idempotent
Schéma d’entrée
{'type': 'object', 'required': ['credential'], 'properties': {'credential': {'type': 'string', 'description': 'The credential to verify (JSON string or JWT)'}}}
Modifié
marketnow_submit_skill
2 October 2026 02:40
Modifié
marketnow_fingerprint_tool
2 October 2026 02:40
Modifié
marketnow_check_revocation
2 October 2026 02:40
Modifié
marketnow_search_skills
2 October 2026 02:40
Modifié
marketnow_check_domain
2 October 2026 02:40
Modifié
marketnow_get_pipeline
2 October 2026 02:40
Modifié
marketnow_list_formats
2 October 2026 02:40
Modifié
marketnow_translate_credential
2 October 2026 02:40
Modifié
marketnow_verify_trust
2 October 2026 02:40
Ajouté
marketnow_submit_skill
30 September 2026 02:40
Ajouté
marketnow_fingerprint_tool
30 September 2026 02:40
Ajouté
marketnow_check_revocation
30 September 2026 02:40
Ajouté
marketnow_search_skills
30 September 2026 02:40
Ajouté
marketnow_check_domain
30 September 2026 02:40
Ajouté
marketnow_get_pipeline
30 September 2026 02:40
Ajouté
marketnow_list_formats
30 September 2026 02:40
Ajouté
marketnow_translate_credential
30 September 2026 02:40
Ajouté
marketnow_verify_trust
30 September 2026 02:40