Repo ecosystem (one owner per concern, split 2026-09-26): this repo owns the ATC protocol — the v3.0 RFC draft (
spec/), the UTS schema, the 36-vector conformance corpus (uta-monorepo/vectors/), the reference implementation (uta-monorepo/), format adapters, plugins, and the Stranger Manifesto. Product code (mcp-server, npmmarketnow-mcp,atc-sdk, integrations) lives inalicelabs-llc/MARKETNOW; the live marketplace (site, catalog data, data pipelines, Vercel deploys of marketnow.site) lives ineddyflores100-lang/marketnow.
The USB-C of agent trust.
UTA translates between ALL trust credential formats used by AI agents via a canonical Universal Trust Schema (UTS).
Like Zapier connects applications, UTA connects trust standards.
Built by Edison Flores & Alejandro Flores at AliceLabs LLC (Wyoming, USA).
Every trust claim in this repo is re-derivable by a stranger, from live public URLs, with no account and no trust in our endpoints:
# 9 checks against Sigstore Rekor's LIVE transparency-log data:
# entry exists · content hash · countersignature · signed tree head ·
# Merkle inclusion proof · C2SP checkpoint — all verified locally.
curl -sL https://www.marketnow.site/uta/conformance/anchors/verify-rekor.mjs -o verify-rekor.mjs
node verify-rekor.mjs
# Full conformance suite (14 vectors, stage scoring, curl + node only):
# https://www.marketnow.site/uta/conformance/Exercised in production, receipts public: we rotated our CA key mn-ca-002 → mn-ca-003 on 2026-09-08 after private-key material was found committed to a public repository (exposure confirmed; no third-party misuse observed). Revocation published same-day, postmortem public: https://marketnow.site/security/incidents/2026-09-08. Three Rekor log entries (logIndex 2762061972, 2764017355, 2764479676) anchor the digests, and the published npm tarball's tar layer rebuilds byte-exact from source (sha256 519d406a…).
Trust that requires membership is not trust. It's a guest list.
Ten build rules for stranger-verifiable agent trust — read it in your language (every version anchored to the same live receipts):
English · Español · Português · Français · Deutsch · Italiano · Русский · 日本語 · 中文 · 한국어 · हिन्दी · العربية · Türkçe
Markdown sources: manifesto/ — one file per language, same content, same receipts.
Rendered right here on GitHub; the marketnow.site/manifesto/ pages ship with the next site deploy.
"Visa has a Trusted Agent Protocol. Mastercard has Verifiable Intent. Here's the layer neither one gives you."
- English — canonical, full version
- العربية
- Deutsch
- Español
- Français
- हिन्दी
- Bahasa Indonesia
- Italiano
- 日本語
- 한국어
- Português
- Русский
- Türkçe
- Tiếng Việt
- 中文
The 2026 gray-market quota trust crisis, documented — plus the receipts-based fix:
- English — You Paid an AI Reseller — Then the Rules Changed Mid-Cycle
- 中文 — 你买的 AI 合租/中转被改规则或跑路?开发者自保清单
- Русский — Оплатили AI-подписку через посредника — а правила изменились посреди цикла?
- Español — Pagaste por Claude o Cursor a un revendedor ¿y las reglas cambiaron a mitad del ciclo?
- Sourced timeline (EN) — The 2026 AI Quota Gray-Market Trust Crisis — A Sourced Timeline
- Series index · Verify a trust card: https://marketnow.site/verify
Release v5.1 — roadmap items 1 & 5 (commit 7fb7db6a, Rekor anchor #4):
- ATC Revocation + Transparency Log (MNR-CRL-1.0) — a signed, append-only revocation registry for Agent Trust Cards and CA keys. The
/api/trust?action=revocationpage used to promise an OCSP responder that returned 404; nowGET /api/ocsp?card_id=…/?kid=…answers for real: VALID / EXPIRED / REVOKED / SUPERSEDED / UNKNOWN, with PERMIT/DENY recommendation, fail-closed semantics, and the CRL signature embedded so any client can verify the signed layer independently (GET /api/crl). Seeded with real events — 3 superseded ATCs + themn-ca-002key compromise (2026-09-08). - Cryptographic Tool Fingerprinting (TFP-1.0) — the OWASP MCP Cheat Sheet control "verify tool descriptions haven't changed", as an MCP tool: SHA-256 over the RFC 8785 JCS canonical form of each tool + a manifest fingerprint for the whole
tools/listsurface + drift reports (added / removed / changed) against pinned manifests. The core defense against tool poisoning and rug-pull redefinitions. - MCP endpoint v1.15.0 (9 public remote tools — discovery/trust surface) and npm
marketnow-mcp@1.15.0(15 local trust/security tools) — remote surface and package surface are different by design: the endpoint exposes public discovery over the live catalog, the package runs client-side against local credentials. The npm package also fixed the brokenrepository.directorylink and upgraded the MCP SDK (DNS-rebinding advisory resolved;npm auditclean). - Interceptor v1.1.0 (
@marketnow/cline-trust-plugin, npm) — revocation gate (fail-closed, 5-min TTL) + per-server tool-surface pinning/verification. - Sentinel semgrep rules v2 — 29 rules: +tool-poisoning (MCP-TP), +exfiltration chains (MCP-EX), +multi-step attack chains (MCP-AC, roadmap v5.4 preview), +stale-trust caching (MCP-RR).
- Rekor anchor #4 (logIndex 2771735480) — the revocation registry itself is anchored in Sigstore's public log; the revocation history is third-party-checkable end-to-end.
Stranger-verifiable trust evidence:
- Rekor transparency anchors (entries #1–#3) — result digests committed to Sigstore's public append-only log; 9 local checks against live third-party data (run the stranger test above)
- Exercised CA key rotation —
mn-ca-002→mn-ca-003(key material found in a public repo; exposure confirmed, no third-party misuse), revocation published same-day — postmortem, verifiers fail-safe inside the window - Reproducible build —
agent-trust-card's tar layer rebuilds byte-exact from source (the.tgzis anchored by digest; the tar layer by rebuild) - New failure vectors —
premature-atc(credential accepted before verification completes),expired-atc(key no longer valid at verify time), stage scoring, published generator CA - Conformance v1.3.3 — 14 public vectors · 24 checks + 10 mutants (runner-under-test) · versioned digests
Domain Reputation Endpoint (/api/reputation) — UTA now answers a second class of trust
question. The Universal Trust API verifies credentials; this endpoint answers
"can I trust this domain before I show it to a human or act on it?"
- Spec:
api/reputation-spec.md· v1.2 engine, stable - Reference implementation:
api/reputation.ts— one file, zero dependencies, hosting-neutral (Node 18+, Deno, Bun, Cloudflare Workers, any edge runtime) - Verdicts:
trusted(95) ·unknown(55) ·caution(35) ·risky(8) — deterministic, transparent reasons, free & keyless, CDN-cacheable 24h - Client parity: identical engine runs in the browser (ProdIntel
services/sourceTrust.ts) — badges render instantly offline, get server-confirmed when reachable - First consumer in production: ProdIntel source safety gate
- v1.2 engine fix: shortener matching is now exact-host/subdomain — v1.1 substring
matching wrongly scored
riskymarketplaces containingt.coinside<name>.com(walmart.com, target.com, homedepot.com, flipkart.com). Cache consumers should key on v1.2.
Code lives in this repo (GitHub is the single source of truth). Deployment is bring-your-own-host.
UTA supports TWO versions of ATC (Agent Trust Card):
| Version | Status | Multi-sig | Spec file | Description |
|---|---|---|---|---|
| ATC/1.0 | Public, stable | Single-sig (Ed25519) | SPEC.md → MARKETNOW repo |
Simple, single-CA credential. SDK: npm agent-trust-card. |
| ATC v3.0 | Draft 00, pre-public review | Multi-format (Ed25519 + EAT-CWT + W3C VC) | spec/RFC-ATC-v3-Draft-00.md |
Multi-sig (N-of-M), multi-format. Backward-compatible with v2.0. Used internally by UTA. |
ATC v3.0 supersedes ATC v2.0 (which itself was the basis for the simpler ATC/1.0 SDK). A v2.0 ATC remains valid; v3.0 verifiers accept v2.0 credentials and treat them as having a single signature.
# Install the uta-verify CLI (npm channel — works for everyone with Node.js)
npm install -g @marketnow/uta-verify
# or: curl -fsSL https://marketnow.site/install.sh | bash
# (the site script wraps the same npm channel; it carries the new flow
# after the next marketnow.site deploy — see eddyflores100-lang/marketnow)
# Or install individual packages
npm install agent-trust-card # ATC/1.0 SDK
npm install -g marketnow-mcp # MCP server (15 trust tools)
npx @marketnow/uta-conformance # run the 14-vector conformance suite
npx @marketnow/sentinel-rules --path . # 29 MCP security rules, zero-dep scan
npx marketnow-audit bit.ly # domain scam-check + ATC + OCSP, CI exit codes| Metric | Value |
|---|---|
| NPM packages | 12 (combined last-week downloads: 4,901+) |
| Conformance (live) | 14 public vectors · 24 checks + 10 mutants · v1.3.5 (npm-synced) |
| Transparency anchors | 3 Rekor log entries (verify-rekor.mjs, 9 checks) |
| CA key rotation | exercised 2026-09-08 (mn-ca-002 → mn-ca-003) — postmortem |
| Test vectors (ATC/1.0) | 5 frozen + manifest — MARKETNOW repo |
| Test vectors (ATC v3.0) | 36 (8 positive + 17 negative + 5 mutation + 6 cross-language) — uta-monorepo/vectors/ |
| Format adapters | 9 (ATC, EAT-AI, ZTA, A2A, MCP Card, W3C VC, OAuth, SPIFFE, X.509) |
| Dev.to articles | 100 (EN + 15 languages) |
| Download channels | 5 (NPM, jsDelivr, unpkg, marketnow.site, GitHub) |
| Package | Version | Description | Downloads (last week) |
|---|---|---|---|
marketnow-mcp |
1.15.0 | MCP server with 15 trust tools (+revocation, +fingerprinting; SDK hardened, npm audit clean) |
1,003/wk |
agent-trust-card |
1.4.1 | ATC/1.0 SDK (issue, verify, inspect) | 616/wk |
marketnow-install-stack |
1.2.1 | Multi-source installer (5 stacks over the live catalog) | 178/wk |
@marketnow/uts |
2.0.3 | Universal Trust Schema | 298/wk |
@marketnow/trust-core |
2.0.3 | Trust Engine core: verification pipeline + behavior/drift + policy + trajectory + cross-agent (92 exports, zero deps) | 313/wk |
@marketnow/trust-adapters |
1.0.4 | 9 format adapters (X509 exported; self-contained, zero deps) | 282/wk |
@marketnow/trust-gateway |
1.0.5 | MCP middleware gateway + ReceiptStore/ReceiptGenerator exported (self-contained, zero deps) | 307/wk |
@marketnow/cline-trust-plugin |
1.1.2 | Cline interceptor: revocation gate + TFP tool-surface pinning | 346/wk |
@marketnow/uta-conformance |
1.3.5 | 14 signed vectors + reference scorer + card generator — npx @marketnow/uta-conformance |
307/wk |
@marketnow/sentinel-rules |
1.1.2 | 29 MCP security rules: semgrep config + zero-dep lite scanner — npx @marketnow/sentinel-rules --path . |
471/wk |
@marketnow/trust-mcp-middleware |
1.0.2 | MCP tools/call wrapper: credential enforcement + signed audit receipts |
319/wk |
@marketnow/trust-observability |
1.0.3 | Zero-dep observability: structured logging, tracing, Prometheus metrics | 461/wk |
@marketnow/uta-verify |
1.0.2 | CLI credential verifier: ATC v3, JWT, VC, A2A, EAT, ZTA, MCP — CI exit codes | new |
marketnow-audit |
1.0.1 | Security audit CLI: domain scam-check, ATC verify, OCSP status, catalog — exit codes for CI (0 PERMIT / 1 DENY / 2 CAUTION) |
new |
- NPM Registry — primary, independent of GitHub
- jsDelivr CDN — free global CDN, mirrors NPM automatically
- unpkg CDN — alternative CDN, also mirrors NPM
- marketnow.site — AliceLabs-owned origin server
- GitHub org —
alicelabs-llc/universal-trust-adapter(this repo)
Three different counts coexist in this ecosystem. They are not three ways of counting the same thing:
| System | Count | What it counts | Where to verify |
|---|---|---|---|
| Sentinel (audit pipeline) | 12 stages / 10 layers | Index certification (L1), static analysis (L1.5–L1.9), deep tarball scan (L2, 29 rules), sandbox (L2.5), runtime monitoring (L3), dependency/secrets/SBOM/policy (L4–L9) | /security/sentinel-v3.0 |
| ATC/1.0 (credential verification) | 10 controls — 8 required + 2 optional | Signature, key selection, expiry, status, revocation… per ATC card | SPEC.md §2 → MARKETNOW repo |
| UTA (interop layer) | 9 format adapters | Credential formats translated through UTS: ATC, EAT-AI, ZTA, A2A, MCP Card, W3C VC, OAuth, SPIFFE, X.509 | /uta |
If a surface says "8-layer audit" anywhere, it is stale — the Sentinel pipeline is 12 stages grouped into 10 audit layers (L1–L9). ATC's "8" is the count of required verification controls (10 total). UTA's number is formats, not layers.
| Layer | What | License |
|---|---|---|
| 1. Plugin Template | Interface + boilerplate for third-party adapters | MIT |
| 2. UTS Specification | Universal Trust Schema (spec + JSON Schema) | CC-BY-NC-ND 4.0 |
| 3. The Engine + Sentinel + Interceptor | TrustEngine core, Sentinel 12-stage / 10-layer audit, eBPF enforcement | AL-1.0 |
# Verify any ATC card (ATC/1.0 or ATC v3.0)
npx -y agent-trust-card verify card.json
# Run the MCP server (works with Claude Desktop, Cursor, Cline, Continue, Aider)
npx -y marketnow-mcp
# Run the conformance suite (no clone needed)
npx -y @marketnow/uta-conformance
# Or from source (atc-sdk lives in the MARKETNOW repo since the 2026-09-26 split):
git clone https://github.com/alicelabs-llc/MARKETNOW
cd MARKETNOW/atc-sdk && npm install && node test/conformance.mjsATC/1.0 (5 frozen): MARKETNOW repo → docs/atc-spec/test-vectors/ — 5 fixtures with canonical JCS bytes per vector + SHA-256 + Ed25519 signature.
ATC v3.0 (36 vectors): uta-monorepo/vectors/ — 8 positive + 17 negative + 5 mutation + 6 cross-language, plus a prompt-injection corpus. MANIFEST with per-vector expected outcomes.
The test CA keypair is intentionally published (including private key) for cross-language reproducibility.
⚠️ TEST ONLY — this private key is intentionally public. It MUST NEVER be trusted in production.ca-test-2exists so any stranger can regenerate and re-sign the conformance vectors in any language. Signatures underca-test-2prove conformance-suite behavior — nothing else. Production CAs (mn-ca-003) are separate keys, never published, and their lifecycle is auditable in the revocation registry and the 2026-09-08 incident postmortem.
- ATC/1.0 Spec: MARKETNOW repo →
docs/atc-spec/SPEC.md - ATC v3.0 RFC Draft:
spec/RFC-ATC-v3-Draft-00.md - UTS v1:
spec/UTS-v1.md·spec/uts-v1.json - Domain Reputation API spec:
api/reputation-spec.md - Universal Trust API spec:
api/trust-api-spec.md - Threat model (STRIDE + MITRE ATLAS):
uta-monorepo/threat-model/THREAT_MODEL.md - Architecture:
docs/ARCHITECTURE.md - License matrix (all components): https://marketnow.site/licensing
- CA incident postmortem 2026-09-08: https://marketnow.site/security/incidents/2026-09-08
- Contributing:
CONTRIBUTING.md - Security policy:
SECURITY.md
- GitHub Discussions: discussions
- Dev.to: @edison_flores_6d2cd381b13 — 96 articles
- Issues: Report a bug
- Email: info@alicelabs.site
| Component | License |
|---|---|
| Plugin template | MIT |
| UTS specification | CC-BY-NC-ND 4.0 |
| Engine + Sentinel + Interceptor | AL-1.0 |
Author: Edison Flores · Email: info@alicelabs.site · Website: https://marketnow.site
Company: AliceLabs LLC (Wyoming, USA)
Dual-licensed under MIT OR Apache-2.0, at your option — free for any use, including commercial use. This repo and all MarketNow npm packages (marketnow-mcp v1.14.0+, agent-trust-card v1.4.0+, @marketnow/*) ship dual-licensed: see LICENSE-MIT and LICENSE-APACHE. Trademarks ("MarketNow", "UTA", "ATC") are reserved by AliceLabs LLC — see NOTICE.