Skip to content

feat: add MarketNow remote MCP server (security) - #5175

Open
eddyflores100-lang wants to merge 1 commit into
docker:mainfrom
eddyflores100-lang:add-marketnow
Open

eddyflores100-lang wants to merge 1 commit into
docker:mainfrom
eddyflores100-lang:add-marketnow

Conversation

@eddyflores100-lang

@eddyflores100-lang eddyflores100-lang commented Sep 20, 2026 •

Copy link
Copy Markdown

MCP Server Information

Server Name: MarketNow
Server URL: https://www.marketnow.site/api/mcp
Brief Description: Free trust layer for AI agents on MCP: credential verification (8 formats incl. JWT, W3C VC, X.509), domain scam-checking (WHOIS age + TLS certificate inspection), tool-definition fingerprinting against tool poisoning (OWASP MCP Top 10), and a 68k+ indexed MCP server registry search. Remote endpoint, zero install, no API key required for public tools.

Basic Requirements

  • Open Source: dual MIT OR Apache-2.0 (LICENSE-MIT + LICENSE-APACHE in repo, commit 0b0310e9)
  • MCP Compliant: MCP 2025-03-26 over streamable HTTP; initialize handshake verified live
  • Active Development: daily commits; latest today (dual-license + npm release alignment). npm packages published today under dual MIT OR Apache-2.0: marketnow-mcp@1.14.0 (https://www.npmjs.com/package/marketnow-mcp) plus 13 companion packages (agent-trust-card@1.4.1, @marketnow/uts@2.0.3, @marketnow/trust-core@2.0.3, …)
  • Docker Artifact: N/A (remote server)
  • Documentation: README + setup instructions + llms-install.md in repo
  • Security Contact: info@alicelabs.site

Submitter Checklist

  • This server meets the basic requirements listed above
  • I understand this will undergo automated and manual review.
  • I have tested the MCP Server using task validate -- --name marketnow (no local Go toolchain; relying on CI validation on this PR)
  • I have built the MCP Server using task build -- --tools marketnow (same as above)
  • If the server requires credentials to test it, I have shared test credentials using this form — N/A, no credentials required

Repository: https://github.com/alicelabs-llc/universal-trust-adapter (dual MIT OR Apache-2.0)

@eddyflores100-lang

eddyflores100-lang commented Sep 27, 2026 •

Copy link
Copy Markdown
Author

Maintainer update — dual submission note:

This remote (hosted) entry is now complemented by a local/containerized submission for the same server: #5263, which packages MarketNow as a public Docker image (ghcr.io/alicelabs-llc/marketnow-mcp — anonymous pull, no login or secret required).

The dual submission is intentional and follows the existing catalog pattern of paired local/remote entries (sentry / sentry-remote, notion / notion-remote, atlassian / atlassian-remote):

Both entries share the same core trust tools (marketnow_verify_trust, marketnow_search_skills, marketnow_check_revocation, marketnow_fingerprint_tool, marketnow_submit_skill): the image entry (#5263) ships the full 15-tool marketnow_* marketplace server (verified via stdio tools/list on v1.15.0), while this hosted entry serves the trust-layer subset (9 tools, verified live today). Happy to consolidate into a single entry if the team prefers one channel — just let us know which one to keep. Thanks for the review!

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant