The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Marketnow listing page.
Repo ecosystem (one owner per concern, split 2026-09-26): this repo owns the ATC protocol — the v3.0 RFC draft (
spec/), the UTS schema, the 36-vector conformance corpus (uta-monorepo/vectors/), the reference implementation (uta-monorepo/), format adapters, plugins, and the Stranger Manifesto. Product code (mcp-server, npmmarketnow-mcp,atc-sdk, integrations) lives inalicelabs-llc/MARKETNOW; the live marketplace (site, catalog data, data pipelines, Vercel deploys of marketnow.site) lives ineddyflores100-lang/marketnow.
The USB-C of agent trust.
UTA translates between ALL trust credential formats used by AI agents via a canonical Universal Trust Schema (UTS).
Like Zapier connects applications, UTA connects trust standards.
Built by Edison Flores & Alejandro Flores at AliceLabs LLC (Wyoming, USA).
Every trust claim in this repo is re-derivable by a stranger, from live public URLs, with no account and no trust in our endpoints:
Exercised in production, receipts public: we rotated our CA key mn-ca-002 → mn-ca-003 on 2026-09-08 after private-key material was found committed to a public repository (exposure confirmed; no third-party misuse observed). Revocation published same-day, postmortem public: https://marketnow.site/security/incidents/2026-09-08. Three Rekor log entries (logIndex 2762061972, 2764017355, 2764479676) anchor the digests, and the published npm tarball's tar layer rebuilds byte-exact from source (sha256 519d406a…).
Trust that requires membership is not trust. It's a guest list.
Ten build rules for stranger-verifiable agent trust — read it in your language (every version anchored to the same live receipts):
English · Español · Português · Français · Deutsch · Italiano · Русский · 日本語 · 中文 · 한국어 · हिन्दी · العربية · Türkçe
Markdown sources: manifesto/ — one file per language, same content, same receipts.
Rendered right here on GitHub; the marketnow.site/manifesto/ pages ship with the next site deploy.
"Visa has a Trusted Agent Protocol. Mastercard has Verifiable Intent. Here's the layer neither one gives you."
The 2026 gray-market quota trust crisis, documented — plus the receipts-based fix:
Release v5.1 — roadmap items 1 & 5 (commit 7fb7db6a, Rekor anchor #4):
/api/trust?action=revocation page used to promise an OCSP responder that returned 404; now GET /api/ocsp?card_id=… / ?kid=… answers for real: VALID / EXPIRED / REVOKED / SUPERSEDED / UNKNOWN, with PERMIT/DENY recommendation, fail-closed semantics, and the CRL signature embedded so any client can verify the signed layer independently (GET /api/crl). Seeded with real events — 3 superseded ATCs + the mn-ca-002 key compromise (2026-09-08).tools/list surface + drift reports (added / removed / changed) against pinned manifests. The core defense against tool poisoning and rug-pull redefinitions.marketnow-mcp@1.15.0 (15 local trust/security tools) — remote surface and package surface are different by design: the endpoint exposes public discovery over the live catalog, the package runs client-side against local credentials. The npm package also fixed the broken repository.directory link and upgraded the MCP SDK (DNS-rebinding advisory resolved; npm audit clean).@marketnow/cline-trust-plugin, npm) — revocation gate (fail-closed, 5-min TTL) + per-server tool-surface pinning/verification.Stranger-verifiable trust evidence:
mn-ca-002 → mn-ca-003 (key material found in a public repo; exposure confirmed, no third-party misuse), revocation published same-day — postmortem, verifiers fail-safe inside the windowagent-trust-card's tar layer rebuilds byte-exact from source (the .tgz is anchored by digest; the tar layer by rebuild)premature-atc (credential accepted before verification completes), expired-atc (key no longer valid at verify time), stage scoring, published generator CADomain Reputation Endpoint (/api/reputation) — UTA now answers a second class of trust
question. The Universal Trust API verifies credentials; this endpoint answers
"can I trust this domain before I show it to a human or act on it?"
api/reputation-spec.md · v1.2 engine, stableapi/reputation.ts — one file, zero
dependencies, hosting-neutral (Node 18+, Deno, Bun, Cloudflare Workers, any edge runtime)trusted (95) · unknown (55) · caution (35) · risky (8) — deterministic,
transparent reasons, free & keyless, CDN-cacheable 24hservices/sourceTrust.ts) — badges render instantly offline, get server-confirmed when reachablerisky marketplaces containing t.co inside <name>.com
(walmart.com, target.com, homedepot.com, flipkart.com). Cache consumers should key on v1.2.Code lives in this repo (GitHub is the single source of truth). Deployment is bring-your-own-host.
UTA supports TWO versions of ATC (Agent Trust Card):
| Version | Status | Multi-sig | Spec file | Description |
|---|---|---|---|---|
| ATC/1.0 | Public, stable | Single-sig (Ed25519) | SPEC.md → MARKETNOW repo | Simple, single-CA credential. SDK: npm agent-trust-card. |
| ATC v3.0 | Draft 00, pre-public review | Multi-format (Ed25519 + EAT-CWT + W3C VC) | spec/RFC-ATC-v3-Draft-00.md | Multi-sig (N-of-M), multi-format. Backward-compatible with v2.0. Used internally by UTA. |
ATC v3.0 supersedes ATC v2.0 (which itself was the basis for the simpler ATC/1.0 SDK). A v2.0 ATC remains valid; v3.0 verifiers accept v2.0 credentials and treat them as having a single signature.
| Metric | Value |
|---|---|
| NPM packages | 12 (combined last-week downloads: 4,901+) |
| Conformance (live) | 14 public vectors · 24 checks + 10 mutants · v1.3.5 (npm-synced) |
| Transparency anchors | 3 Rekor log entries (verify-rekor.mjs, 9 checks) |
| CA key rotation | exercised 2026-09-08 (mn-ca-002 → mn-ca-003) — postmortem |
| Test vectors (ATC/1.0) | 5 frozen + manifest — MARKETNOW repo |
| Test vectors (ATC v3.0) | 36 (8 positive + 17 negative + 5 mutation + 6 cross-language) — uta-monorepo/vectors/ |
| Format adapters | 9 (ATC, EAT-AI, ZTA, A2A, MCP Card, W3C VC, OAuth, SPIFFE, X.509) |
| Dev.to articles | 100 (EN + 15 languages) |
| Download channels | 5 (NPM, jsDelivr, unpkg, marketnow.site, GitHub) |
| Package | Version | Description | Downloads (last week) |
|---|---|---|---|
marketnow-mcp | 1.15.0 | MCP server with 15 trust tools (+revocation, +fingerprinting; SDK hardened, npm audit clean) | 1,003/wk |
agent-trust-card | 1.4.1 | ATC/1.0 SDK (issue, verify, inspect) | 616/wk |
marketnow-install-stack | 1.2.1 | Multi-source installer (5 stacks over the live catalog) | 178/wk |
@marketnow/uts | 2.0.3 | Universal Trust Schema | 298/wk |
@marketnow/trust-core | 2.0.3 | Trust Engine core: verification pipeline + behavior/drift + policy + trajectory + cross-agent (92 exports, zero deps) | 313/wk |
@marketnow/trust-adapters | 1.0.4 | 9 format adapters (X509 exported; self-contained, zero deps) | 282/wk |
@marketnow/trust-gateway | 1.0.5 | MCP middleware gateway + ReceiptStore/ReceiptGenerator exported (self-contained, zero deps) | 307/wk |
@marketnow/cline-trust-plugin | 1.1.2 | Cline interceptor: revocation gate + TFP tool-surface pinning | 346/wk |
@marketnow/uta-conformance | 1.3.5 | 14 signed vectors + reference scorer + card generator — npx @marketnow/uta-conformance | 307/wk |
@marketnow/sentinel-rules | 1.1.2 | 29 MCP security rules: semgrep config + zero-dep lite scanner — npx @marketnow/sentinel-rules --path . | 471/wk |
@marketnow/trust-mcp-middleware | 1.0.2 | MCP tools/call wrapper: credential enforcement + signed audit receipts | 319/wk |
@marketnow/trust-observability | 1.0.3 | Zero-dep observability: structured logging, tracing, Prometheus metrics | 461/wk |
@marketnow/uta-verify | 1.0.2 | CLI credential verifier: ATC v3, JWT, VC, A2A, EAT, ZTA, MCP — CI exit codes | new |
marketnow-audit | 1.0.1 | Security audit CLI: domain scam-check, ATC verify, OCSP status, catalog — exit codes for CI (0 PERMIT / 1 DENY / 2 CAUTION) | new |
alicelabs-llc/universal-trust-adapter (this repo)Three different counts coexist in this ecosystem. They are not three ways of counting the same thing:
| System | Count | What it counts | Where to verify |
|---|---|---|---|
| Sentinel (audit pipeline) | 12 stages / 10 layers | Index certification (L1), static analysis (L1.5–L1.9), deep tarball scan (L2, 29 rules), sandbox (L2.5), runtime monitoring (L3), dependency/secrets/SBOM/policy (L4–L9) | /security/sentinel-v3.0 |
| ATC/1.0 (credential verification) | 10 controls — 8 required + 2 optional | Signature, key selection, expiry, status, revocation… per ATC card | SPEC.md §2 → MARKETNOW repo |
| UTA (interop layer) | 9 format adapters | Credential formats translated through UTS: ATC, EAT-AI, ZTA, A2A, MCP Card, W3C VC, OAuth, SPIFFE, X.509 | /uta |
If a surface says "8-layer audit" anywhere, it is stale — the Sentinel pipeline is 12 stages grouped into 10 audit layers (L1–L9). ATC's "8" is the count of required verification controls (10 total). UTA's number is formats, not layers.
| Layer | What | License |
|---|---|---|
| 1. Plugin Template | Interface + boilerplate for third-party adapters | MIT |
| 2. UTS Specification | Universal Trust Schema (spec + JSON Schema) | CC-BY-NC-ND 4.0 |
| 3. The Engine + Sentinel + Interceptor | TrustEngine core, Sentinel 12-stage / 10-layer audit, eBPF enforcement | AL-1.0 |
ATC/1.0 (5 frozen): MARKETNOW repo → docs/atc-spec/test-vectors/ — 5 fixtures with canonical JCS bytes per vector + SHA-256 + Ed25519 signature.
ATC v3.0 (36 vectors): uta-monorepo/vectors/ — 8 positive + 17 negative + 5 mutation + 6 cross-language, plus a prompt-injection corpus. MANIFEST with per-vector expected outcomes.
The test CA keypair is intentionally published (including private key) for cross-language reproducibility.
⚠️ TEST ONLY — this private key is intentionally public. It MUST NEVER be trusted in production.
ca-test-2exists so any stranger can regenerate and re-sign the conformance vectors in any language. Signatures underca-test-2prove conformance-suite behavior — nothing else. Production CAs (mn-ca-003) are separate keys, never published, and their lifecycle is auditable in the revocation registry and the 2026-09-08 incident postmortem.
docs/atc-spec/SPEC.mdspec/RFC-ATC-v3-Draft-00.mdspec/UTS-v1.md · spec/uts-v1.jsonapi/reputation-spec.mdapi/trust-api-spec.mduta-monorepo/threat-model/THREAT_MODEL.mddocs/ARCHITECTURE.mdCONTRIBUTING.mdSECURITY.md| Component | License |
|---|---|
| Plugin template | MIT |
| UTS specification | CC-BY-NC-ND 4.0 |
| Engine + Sentinel + Interceptor | AL-1.0 |
Author: Edison Flores · Email: info@alicelabs.site · Website: https://marketnow.site
Company: AliceLabs LLC (Wyoming, USA)
Dual-licensed under MIT OR Apache-2.0, at your option — free for any use, including commercial use. This repo and all MarketNow npm packages (marketnow-mcp v1.14.0+, agent-trust-card v1.4.0+, @marketnow/*) ship dual-licensed: see LICENSE-MIT and LICENSE-APACHE. Trademarks ("MarketNow", "UTA", "ATC") are reserved by AliceLabs LLC — see NOTICE.