MCP marketplace with 8-layer Sentinel security audit + ATC (Agent Trust Card) — SSL certificates for AI agents. 7,063 real skills, all free.
claude mcp add marketnow -- npx -y marketnow-mcp{
"mcpServers": {
"marketnow": {
"command": "npx",
"args": ["-y", "marketnow-mcp"]
}
}
}MCP Servers overview
[](https://github.com/edgarfloresguerra2011-a11y/marketnow)
[](https://www.npmjs.com/package/marketnow-mcp)
[](https://github.com/edgarfloresguerra2011-a11y/marketnow/blob/master/LICENSE)
[](https://marketnow.site/security)
# MarketNow — Trust Layer for Agent Commerce
> ⭐ **If MarketNow is useful to you, please star the repo. It helps other developers discover it.**
> **7,063 MCP servers. Each Sentinel-audited with 6 layers (L1.5 → L2.5 gVisor sandbox). Signed SHA-256 certificates. Public verification at marketnow.site/verify.**
<!-- CANONICAL METADATA — for crawlers and directories that scrape this README.
If you are maintaining an external directory listing for MarketNow,
use these values as the source of truth. Last updated: 2026-07-06. -->
| Field | Value |
|---|---|
| **Name** | MarketNow |
| **Tagline** | Trust layer for agent commerce — every skill Sentinel-certified |
| **Description** | MarketNow is the first MCP marketplace with security certification. Every one of 7,063 MCP servers is audited by Sentinel (6-layer pipeline: L1.5 metadata + L1.6 Semgrep/secrets/OSV + L2 active probe + L2.5 gVisor sandbox) and gets a signed SHA-256 certificate, publicly verifiable at marketnow.site/verify. B2B pricing: Community (Free) / Team ($99/mo) / Enterprise (Custom). AliceLabs LLC proprietary, maintained by AliceLabs LLC (Wyoming, USA). |
| **Total skills** | 7,063 |
| **Certified skills** | 7,063 (100%) |
| **Free skills** | 65 |
| **Categories** | 23 |
| **Pricing** | B2B: Community (Free) / Team ($99/mo, COMING SOON) / Enterprise (Custom) |
| **Payment methods** | Stripe (credit card) + USDC on Base |
| **Languages** | EN, ES, ZH, PT, FR |
| **License** | AliceLabs LLC Proprietary |
| **Maintainer** | AliceLabs LLC (Wyoming, USA) — founder Edison Flores |
| **MCP server** | `npx -y marketnow-mcp` |
| **npm** | https://www.npmjs.com/package/marketnow-mcp |
| **GitHub** | https://github.com/edgarfloresguerra2011-a11y/marketnow |
| **Website** | https://marketnow.site |
| **Verify certificate** | https://marketnow.site/verify |
| **Transparency dashboard** | https://marketnow.site/sentinel-transparency |
| **API docs** | https://marketnow.site/api/agent.json |
| **Standards** | x402 (implementing), AP2 (implementing), MCP Server Cards (monitoring) |
| **Sentinel layers** | L1.5 (6 metadata checks) + L1.6 (18 Semgrep rules + 18 secret patterns + OSV API) + L2 v2.0 (active MCP probe, 60+ adversarial inputs) + L2.5 (gVisor sandbox: --runtime=runsc, userspace kernel) + L3 (Firecracker microVM, Q1 2027) + L4 (supply chain attestation, Q4 2026) + L5 (third-party audit, Q3 2027) |
<!-- END CANONICAL METADATA -->
[](https://www.npmjs.com/package/marketnow-mcp)
[](https://github.com/edgarfloresguerra2011-a11y/marketnow/blob/master/LICENSE)
[](https://marketnow.site/sentinel-transparency)
## 🤖 What is MarketNow?
MarketNow is the open marketplace for MCP-compatible agent skills. It allows any agent (Claude Desktop, Cursor, Cline, VS Code) to search, discover, and install **Sentinel-certified** skills via the Model Context Protocol.
**The code is open source. What you pay for is trust, certification, and integration.**
## 🛡️ Sentinel Certification
Every skill in MarketNow is audited by Sentinel, a 6-layer security pipeline:
### L1.5 — Metadata Checks (real-time, ~200ms on Vercel)
- AUTH (does the server require authentication?)
- Tool description injection (prompt injection patterns)
- Input validation (fs/db/http access detection)
- CORS policy
- OAuth scopes
- Rate limiting + error leakage
### L1.6 — Static Analysis (real-time + weekly batch)
- 18 Semgrep-equivalent rules (prompt injection, command injection, SSRF, path traversal, tool forgery)
- 18 secret patterns (Stripe, AWS, GitHub, JWT, private keys, wallet mnemonics)
- OSV API real-time dependency vulnerability check
### L2 v2.0 — Active MCP Probe + Docker Sandbox (async via GitHub Actions)
L2.5 adds gVisor (runsc) userspace kernel isolation on top of Docker. The MCP server never touches the host kernel.
Runs the actual MCP server in isolation:
```bash
docker run --rm \
--network none \
--read-only \
--cap-drop ALL \
--security-opt no-new-privileges \
--memory 256m --cpus 0.5 \
mcp-audit-target
```
Analyzes stdout for: network attempts, fs writes, process spawns, credential leakage, crashes, dynamic imports.
### Results (live at [marketnow.site/sentinel-transparency](https://marketnow.site/sentinel-transparency))
| Risk Level | Count | Score |
|---|---|---|
| Low | 6 | 10/10 |
| Medium | 8,473 | 6-9/10 |
| High | 92 | 2-4/10 |
| Critical | 11 | 0-1/10 |
**L2 coverage**: 206 of 7,063 skills have L2.5 gVisor sandbox results. The remaining 8,558 are certified with L1.5+L1.6 (static analysis). L2 coverage grows weekly via automated GitHub Actions.
Each skill gets a **signed SHA-256 certificate** with:
- `certificate_id` (MN-SC-2026-XXXXXXX)
- `overall_score` (0-10)
- `risk_level` (low/medium/high/critical)
- 7-day validity (regenerated weekly by GitHub Actions cron)
**Verify any certificate**: https://marketnow.site/verify
**Transparency dashboard**: https://marketnow.site/sentinel-transparency
**All certificates**: [_data/sentinel_certificates/](./_data/sentinel_certificates/)
### Markdown Badges
Skill authors can embed a certified badge in their READMEs:
```markdown
[](https://marketnow.site/skill/mn-gen-00003)
```
## 📊 Stats
| Metric | Value |
|---|---|
| Total skills | 7,063 |
| Certified skills | 7,063 (100%) |
| Categories | 61 |
| Free skills | 65 |
| L2.5 sandbox runs | 206 |
| Languages | EN, ES, ZH, PT, FR |
| MCP server tools | 5 |
## 🚀 Quick Start
### Install MCP Server (Claude Desktop, Cursor, Cline)
```json
{
"mcpServers": {
"marketnow": {
"command": "npx",
"args": ["-y", "marketnow-mcp"]
}
}
}
```
Now your agent can:
- Search 7,063 certified skills by query, category, or language
- Get full skill details with system prompts and Sentinel security reports
- Verify any skill's signed certificate
- Get install commands for any skill
### Verify a Certificate
```bash
# Check any skill's certificate via API
curl "https://marketnow.site/api/audit-skill?certificate=1&skillId=mn-gen-00003" | jq
# Or verify visually at:
# https://marketnow.site/verify?skillId=mn-gen-00003
```
### Search Skills
```bash
# Search for web scrapers
curl "https://marketnow.site/api/search?q=scrape" | jq
# Search in Chinese
curl "https://marketnow.site/api/search?q=数据库&language=zh" | jq
```
## 💰 Business model — Sentinel subscriptions for sellers, free marketplace for everyone else
**MarketNow does NOT sell skills.** We administer a free marketplace of 7,063 MCP servers. All skills are free to install and use.
**Our revenue comes from sellers** who want to list/sell THEIR skills on MarketNow. They subscribe to Sentinel (the security audit pipeline) and we take a commission on each sale.
### Seller tiers (Sentinel subscriptions)
| Tier | Price | Max skills | Includes |
|---|---|---|---|
| **FREE** | $0 | 3 | Basic Sentinel L1 scan, standard review queue (24-48h) |
| **PRO** | $9.99/mo | 25 | Priority Sentinel scan (<6h), featured badge, analytics dashboard |
| **ENTERPRISE** | $49.99/mo | unlimited | Instant Sentinel scan (<1h), API access, dedicated account manager, custom commission |
### Add-ons
- **Featured Listing** — $4.99 / 30 days (boost in search results)
- **Verified Seller Badge** — $19.99 one-time (KYC verification, ✓ badge)
- **Priority Review** — $2.99 / skill (skip queue, <6h review)
- **Storage fee** — $0.50/skill/month after 3 skills (FREE tier only)
### Commission on sales
| Party | Share |
|---|---|
| Seller | 80% |
| MarketNow | 20% (15% if affiliate is used) |
| Affiliate | 5% (deducted from MarketNow's share) |
### Affiliate program
5% commission on every sale you refer. Monthly payouts via Stripe Connect (min $50 threshold).
**Sign up as a seller:** https://marketnow.site/submit
## 📡 Public API (no auth required)
| Endpoint | Description |
|---|---|
| `GET /api/skills.json` | All 7,063 skills (bulk download) |
| `GET /api/search?q=query` | Server-side search with relevance scoring |
| `GET /api/free-skills.json` | 65 free skills |
| `GET /api/categories.json` | 61 categories with counts |
| `GET /api/manifest.json` | Marketplace metadata |
| `GET /api/agent.json` | Machine-readable agent instructions |
| `POST /api/audit-skill` | Run Sentinel L1.5+L1.6+L2+L2.5 real-time audit |
| `GET /api/audit-skill?certificate=1&skillId=X` | Retrieve signed Sentinel certificate |
| `GET /api/audit-skill?sentinel-status=1` | Aggregate Sentinel status (batch audit + L2 coverage + certified count) |
| `GET /api/verify-purchase?sessionId=X` | Verify a Stripe purchase |
| `GET /.well-known/mcp/server-card.json` | MCP server discovery |
## 🔧 MCP Server Tools
| Tool | Description |
|---|---|
| `search_skills` | Search by query, category, language |
| `get_skill` | Get full details (system prompt, sentinel, setup) |
| `list_categories` | List all 61 categories |
| `get_manifest` | Marketplace metadata |
| `get_install_command` | Get npx install command |
## 🔗 Links
- **Website**: https://marketnow.site
- **Verify a certificate**: https://marketnow.site/verify
- **Transparency dashboard**: https://marketnow.site/sentinel-tranWhat people ask about marketnow
What is edgarfloresguerra2011-a11y/marketnow?
+
edgarfloresguerra2011-a11y/marketnow is mcp servers for the Claude AI ecosystem. MCP marketplace with 8-layer Sentinel security audit + ATC (Agent Trust Card) — SSL certificates for AI agents. 7,063 real skills, all free. It has 1 GitHub stars and was last updated today.
How do I install marketnow?
+
You can install marketnow by cloning the repository (https://github.com/edgarfloresguerra2011-a11y/marketnow) or following the README instructions on GitHub. ClaudeWave also provides quick install blocks on this page.
Is edgarfloresguerra2011-a11y/marketnow safe to use?
+
edgarfloresguerra2011-a11y/marketnow has not been audited yet by our security agent. Review the original repository on GitHub before using it in production.
Who maintains edgarfloresguerra2011-a11y/marketnow?
+
edgarfloresguerra2011-a11y/marketnow is maintained by edgarfloresguerra2011-a11y. The last recorded GitHub activity is from today, with 13 open issues.
Are there alternatives to marketnow?
+
Yes. On ClaudeWave you can browse similar mcp servers at /categories/mcp, sorted by popularity or recent activity.
Deploy marketnow to your cloud
Ship this repo to production in minutes. Each platform spins up its own environment with editable env vars.
Maintain this repo? Add a badge to your README
Drop the badge into your GitHub README to show it's tracked on ClaudeWave. Each badge links back to this page and reflects the live Trust Score.
[](https://claudewave.com/repo/edgarfloresguerra2011-a11y-marketnow)<a href="https://claudewave.com/repo/edgarfloresguerra2011-a11y-marketnow"><img src="https://claudewave.com/api/badge/edgarfloresguerra2011-a11y-marketnow" alt="Featured on ClaudeWave: edgarfloresguerra2011-a11y/marketnow" width="320" height="64" /></a>More MCP Servers
Fair-code workflow automation platform with native AI capabilities. Combine visual building with custom code, self-host or cloud, 400+ integrations.
User-friendly AI Interface (Supports Ollama, OpenAI API, ...)
An open-source AI agent that brings the power of Gemini directly into your terminal.
The fastest path to AI-powered full stack observability, even for lean teams.
🕷️ An adaptive Web Scraping framework that handles everything from a single request to a full-scale crawl!
Real-time global intelligence dashboard. AI-powered news aggregation, geopolitical monitoring, and infrastructure tracking in a unified situational awareness interface