Universal Trust Adapter (UTA)

MCP serverSecurity

Gives your agent access to a library of vetted automation skills plus checks that its tools are safe before running them.

Unavailable. This server has no hosted endpoint yet, so ahel can't serve it.

Add to setup to save this item as a reference. ahel cannot run it, and signing in will not install it.

About this server

68k+ security-audited MCP skills + free agent trust layer: signed ATC cards, tool gating, audits.

Getting started

  1. Save this item in Your setup as a reference.
  2. Read the source or reference documentation for its setup requirements. Saving it here does not connect it to your AI.
  3. Check this page for availability before trying to install it through ahel.

From the project's README

As published by alicelabs-llc/universal-trust-adapter in README.md.

Repo ecosystem (one owner per concern, split 2026-09-26): this repo owns the ATC protocol — the v3.0 RFC draft (spec/), the UTS schema, the 36-vector conformance corpus (uta-monorepo/vectors/), the reference implementation (uta-monorepo/), format adapters, plugins, and the Stranger Manifesto. Product code (mcp-server, npm marketnow-mcp, atc-sdk, integrations) lives in alicelabs-llc/MARKETNOW; the live marketplace (site, catalog data, data pipelines, Vercel deploys of marketnow.site) lives in eddyflores100-lang/marketnow.

The USB-C of agent trust.

UTA translates between ALL trust credential formats used by AI agents via a canonical Universal Trust Schema (UTS).

Like Zapier connects applications, UTA connects trust standards.

Built by Edison Flores & Alejandro Flores at AliceLabs LLC (Wyoming, USA).


⚡ Verify our claims — the stranger test (30 seconds)

Every trust claim in this repo is re-derivable by a stranger, from live public URLs, with no account and no trust in our endpoints:

# 9 checks against Sigstore Rekor's LIVE transparency-log data:
# entry exists · content hash · countersignature · signed tree head ·
# Merkle inclusion proof · C2SP checkpoint — all verified locally.
curl -sL https://www.marketnow.site/uta/conformance/anchors/verify-rekor.mjs -o verify-rekor.mjs
node verify-rekor.mjs

# Full conformance suite (14 vectors, stage scoring, curl + node only):
# https://www.marketnow.site/uta/conformance/

Exercised in production, receipts public: we rotated our CA key mn-ca-002 → mn-ca-003 on 2026-09-08 after private-key material was found committed to a public repository (exposure confirmed; no third-party misuse observed). Revocation published same-day, postmortem public: https://marketnow.site/security/incidents/2026-09-08. Three Rekor log entries (logIndex 2762061972, 2764017355, 2764479676) anchor the digests, and the published npm tarball's tar layer rebuilds byte-exact from source (sha256 519d406a…).


🌐 The Stranger Manifesto — 13 languages

Trust that requires membership is not trust. It's a guest list.

Ten build rules for stranger-verifiable agent trust — read it in your language (every version anchored to the same live receipts):

English · Español · Português · Français · Deutsch · Italiano · Русский · 日本語 · 中文 · 한국어 · हिन्दी · العربية · Türkçe

Markdown sources: manifesto/ — one file per language, same content, same receipts. Rendered right here on GitHub; the marketnow.site/manifesto/ pages ship with the next site deploy.

🌍 Visa & Mastercard article — 14 languages

"Visa has a Trusted Agent Protocol. Mastercard has Verifiable Intent. Here's the layer neither one gives you."

🌍 Global Trust Series (multi-language, 2026-09-08)

The 2026 gray-market quota trust crisis, documented — plus the receipts-based fix:

  • English — You Paid an AI Reseller — Then the Rules Changed Mid-Cycle
  • 中文 — 你买的 AI 合租/中转被改规则或跑路?开发者自保清单
  • Русский — Оплатили AI-подписку через посредника — а правила изменились посреди цикла?
  • Español — Pagaste por Claude o Cursor a un revendedor ¿y las reglas cambiaron a mitad del ciclo?
  • Sourced timeline (EN) — The 2026 AI Quota Gray-Market Trust Crisis — A Sourced Timeline
  • Series index · Verify a trust card: https://marketnow.site/verify

🆕 What's new — v5.1 (revocation that answers + tool fingerprinting)

Release v5.1 — roadmap items 1 & 5 (commit 7fb7db6a, Rekor anchor #4):

  • ATC Revocation + Transparency Log (MNR-CRL-1.0) — a signed, append-only revocation registry for Agent Trust Cards and CA keys. The /api/trust?action=revocation page used to promise an OCSP responder that returned 404; now GET /api/ocsp?card_id=… / ?kid=… answers for real: VALID / EXPIRED / REVOKED / SUPERSEDED / UNKNOWN, with PERMIT/DENY recommendation, fail-closed semantics, and the CRL signature embedded so any client can verify the signed layer independently (GET /api/crl). Seeded with real events — 3 superseded ATCs + the mn-ca-002 key compromise (2026-09-08).
  • Cryptographic Tool Fingerprinting (TFP-1.0) — the OWASP MCP Cheat Sheet control "verify tool descriptions haven't changed", as an MCP tool: SHA-256 over the RFC 8785 JCS canonical form of each tool + a manifest fingerprint for the whole tools/list surface + drift reports (added / removed / changed) against pinned manifests. The core defense against tool poisoning and rug-pull redefinitions.
  • MCP endpoint v1.15.0 (9 public remote tools — discovery/trust surface) and npm marketnow-mcp@1.15.0 (15 local trust/security tools) — remote surface and package surface are different by design: the endpoint exposes public discovery over the live catalog, the package runs client-side against local credentials. The npm package also fixed the broken repository.directory link and upgraded the MCP SDK (DNS-rebinding advisory resolved; npm audit clean).
  • Interceptor v1.1.0 (@marketnow/cline-trust-plugin, npm) — revocation gate (fail-closed, 5-min TTL) + per-server tool-surface pinning/verification.
  • Sentinel semgrep rules v2 — 29 rules: +tool-poisoning (MCP-TP), +exfiltration chains (MCP-EX), +multi-step attack chains (MCP-AC, roadmap v5.4 preview), +stale-trust caching (MCP-RR).
  • Rekor anchor #4 (logIndex 2771735480) — the revocation registry itself is anchored in Sigstore's public log; the revocation history is third-party-checkable end-to-end.

v1.3.3 — the receipts release (previous)

Stranger-verifiable trust evidence:

  • Rekor transparency anchors (entries #1–#3) — result digests committed to Sigstore's public append-only log; 9 local checks against live third-party data (run the stranger test above)
  • Exercised CA key rotation — mn-ca-002 → mn-ca-003 (key material found in a public repo; exposure confirmed, no third-party misuse), revocation published same-day — postmortem, verifiers fail-safe inside the window
  • Reproducible build — agent-trust-card's tar layer rebuilds byte-exact from source (the .tgz is anchored by digest; the tar layer by rebuild)
  • New failure vectors — premature-atc (credential accepted before verification completes), expired-atc (key no longer valid at verify time), stage scoring, published generator CA
  • Conformance v1.3.3 — 14 public vectors · 24 checks + 10 mutants (runner-under-test) · versioned digests

v1.2.0 — Domain Reputation Endpoint (previous)

Domain Reputation Endpoint (/api/reputation) — UTA now answers a second class of trust question. The Universal Trust API verifies credentials; this endpoint answers "can I trust this domain before I show it to a human or act on it?"

  • Spec: api/reputation-spec.md · v1.2 engine, stable
  • Reference implementation: api/reputation.ts — one file, zero dependencies, hosting-neutral (Node 18+, Deno, Bun, Cloudflare Workers, any edge runtime)
  • Verdicts: trusted (95) · unknown (55) · caution (35) · risky (8) — deterministic, transparent reasons, free & keyless, CDN-cacheable 24h
  • Client parity: identical engine runs in the browser (ProdIntel services/sourceTrust.ts) — badges render instantly offline, get server-confirmed when reachable
  • First consumer in production: ProdIntel source safety gate
  • v1.2 engine fix: shortener matching is now exact-host/subdomain — v1.1 substring matching wrongly scored risky marketplaces containing t.co inside <name>.com (walmart.com, target.com, homedepot.com, flipkart.com). Cache consumers should key on v1.2.

Code lives in this repo (GitHub is the single source of truth). Deployment is bring-your-own-host.


ATC Versions in this repo

UTA supports TWO versions of ATC (Agent Trust Card):

VersionStatusMulti-sigSpec fileDescription
ATC/1.0Public, stableSingle-sig (Ed25519)SPEC.md → MARKETNOW repoSimple, single-CA credential. SDK: npm agent-trust-card.
ATC v3.0Draft 00, pre-public reviewMulti-format (Ed25519 + EAT-CWT + W3C VC)spec/RFC-ATC-v3-Draft-00.mdMulti-sig (N-of-M), multi-format. Backward-compatible with v2.0. Used internally by UTA.

ATC v3.0 supersedes ATC v2.0 (which itself was the basis for the simpler ATC/1.0 SDK). A v2.0 ATC remains valid; v3.0 verifiers accept v2.0 credentials and treat them as having a single signature.


🚀 Quick install

# Install the uta-verify CLI (npm channel — works for everyone with Node.js)
npm install -g @marketnow/uta-verify
# or: curl -fsSL https://marketnow.site/install.sh | bash
#    (the site script wraps the same npm channel; it carries the new flow
#     after the next marketnow.site deploy — see eddyflores100-lang/marketnow)

# Or install individual packages
npm install agent-trust-card        # ATC/1.0 SDK
npm install -g marketnow-mcp       # MCP server (15 trust tools)
npx @marketnow/uta-conformance    # run the 14-vector conformance suite
npx @marketnow/sentinel-rules --path .  # 29 MCP security rules, zero-dep scan
npx marketnow-audit bit.ly        # domain scam-check + ATC + OCSP, CI exit codes

📊 Project stats

MetricValue
NPM packages12 (combined last-week downloads: 4,901+)
Conformance (live)14 public vectors · 24 checks + 10 mutants · v1.3.5 (npm-synced)
Transparency anchors3 Rekor log entries (verify-rekor.mjs, 9 checks)
CA key rotationexercised 2026-09-08 (mn-ca-002 → mn-ca-003) — postmortem
Test vectors (ATC/1.0)5 frozen + manifest — MARKETNOW repo
Test vectors (ATC v3.0)36 (8 positive + 17 negative + 5 mutation + 6 cross-language) — uta-monorepo/vectors/
Format adapters9 (ATC, EAT-AI, ZTA, A2A, MCP Card, W3C VC, OAuth, SPIFFE, X.509)
Dev.to articles100 (EN + 15 languages)
Download channels5 (NPM, jsDelivr, unpkg, marketnow.site, GitHub)

📦 Packages

PackageVersionDescriptionDownloads (last week)
marketnow-mcp1.15.0MCP server with 15 trust tools (+revocation, +fingerprinting; SDK hardened, npm audit clean)1,003/wk
agent-trust-card1.4.1ATC/1.0 SDK (issue, verify, inspect)616/wk
marketnow-install-stack1.2.1Multi-source installer (5 stacks over the live catalog)178/wk
@marketnow/uts2.0.3Universal Trust Schema298/wk
@marketnow/trust-core2.0.3Trust Engine core: verification pipeline + behavior/drift + policy + trajectory + cross-agent (92 exports, zero deps)313/wk
@marketnow/trust-adapters1.0.49 format adapters (X509 exported; self-contained, zero deps)282/wk
@marketnow/trust-gateway1.0.5MCP middleware gateway + ReceiptStore/ReceiptGenerator exported (self-contained, zero deps)307/wk
@marketnow/cline-trust-plugin1.1.2Cline interceptor: revocation gate + TFP tool-surface pinning346/wk
@marketnow/uta-conformance1.3.514 signed vectors + reference scorer + card generator — npx @marketnow/uta-conformance307/wk
@marketnow/sentinel-rules1.1.229 MCP security rules: semgrep config + zero-dep lite scanner — npx @marketnow/sentinel-rules --path .471/wk
@marketnow/trust-mcp-middleware1.0.2MCP tools/call wrapper: credential enforcement + signed audit receipts319/wk
@marketnow/trust-observability1.0.3Zero-dep observability: structured logging, tracing, Prometheus metrics461/wk
@marketnow/uta-verify1.0.2CLI credential verifier: ATC v3, JWT, VC, A2A, EAT, ZTA, MCP — CI exit codesnew
marketnow-audit1.0.1Security audit CLI: domain scam-check, ATC verify, OCSP status, catalog — exit codes for CI (0 PERMIT / 1 DENY / 2 CAUTION)new

🛡️ 5 Anti-ban download channels

  1. NPM Registry — primary, independent of GitHub
  2. jsDelivr CDN — free global CDN, mirrors NPM automatically
  3. unpkg CDN — alternative CDN, also mirrors NPM
  4. marketnow.site — AliceLabs-owned origin server
  5. GitHub org — alicelabs-llc/universal-trust-adapter (this repo)

🔢 Taxonomy — which count belongs to which system

Three different counts coexist in this ecosystem. They are not three ways of counting the same thing:

SystemCountWhat it countsWhere to verify
Sentinel (audit pipeline)12 stages / 10 layersIndex certification (L1), static analysis (L1.5–L1.9), deep tarball scan (L2, 29 rules), sandbox (L2.5), runtime monitoring (L3), dependency/secrets/SBOM/policy (L4–L9)/security/sentinel-v3.0
ATC/1.0 (credential verification)10 controls — 8 required + 2 optionalSignature, key selection, expiry, status, revocation… per ATC cardSPEC.md §2 → MARKETNOW repo
UTA (interop layer)9 format adaptersCredential formats translated through UTS: ATC, EAT-AI, ZTA, A2A, MCP Card, W3C VC, OAuth, SPIFFE, X.509/uta

If a surface says "8-layer audit" anywhere, it is stale — the Sentinel pipeline is 12 stages grouped into 10 audit layers (L1–L9). ATC's "8" is the count of required verification controls (10 total). UTA's number is formats, not layers.

📐 Open-Core Architecture

LayerWhatLicense
1. Plugin TemplateInterface + boilerplate for third-party adaptersMIT
2. UTS SpecificationUniversal Trust Schema (spec + JSON Schema)CC-BY-NC-ND 4.0
3. The Engine + Sentinel + InterceptorTrustEngine core, Sentinel 12-stage / 10-layer audit, eBPF enforcementAL-1.0

🧪 Try it

# Verify any ATC card (ATC/1.0 or ATC v3.0)
npx -y agent-trust-card verify card.json

# Run the MCP server (works with Claude Desktop, Cursor, Cline, Continue, Aider)
npx -y marketnow-mcp

# Run the conformance suite (no clone needed)
npx -y @marketnow/uta-conformance

# Or from source (atc-sdk lives in the MARKETNOW repo since the 2026-09-26 split):
git clone https://github.com/alicelabs-llc/MARKETNOW
cd MARKETNOW/atc-sdk && npm install && node test/conformance.mjs

🧬 Test vectors

ATC/1.0 (5 frozen): MARKETNOW repo → docs/atc-spec/test-vectors/ — 5 fixtures with canonical JCS bytes per vector + SHA-256 + Ed25519 signature.

ATC v3.0 (36 vectors): uta-monorepo/vectors/ — 8 positive + 17 negative + 5 mutation + 6 cross-language, plus a prompt-injection corpus. MANIFEST with per-vector expected outcomes.

The test CA keypair is intentionally published (including private key) for cross-language reproducibility.

⚠️ TEST ONLY — this private key is intentionally public. It MUST NEVER be trusted in production. ca-test-2 exists so any stranger can regenerate and re-sign the conformance vectors in any language. Signatures under ca-test-2 prove conformance-suite behavior — nothing else. Production CAs (mn-ca-003) are separate keys, never published, and their lifecycle is auditable in the revocation registry and the 2026-09-08 incident postmortem.

📋 Specs & docs

🌐 Community

📄 License

ComponentLicense
Plugin templateMIT
UTS specificationCC-BY-NC-ND 4.0
Engine + Sentinel + InterceptorAL-1.0

Author: Edison Flores · Email: info@alicelabs.site · Website: https://marketnow.site
Company: AliceLabs LLC (Wyoming, USA)

License

Shortened here. Read the whole README on GitHub.

Signals

GitHub stars
1
Forks
1
Last commit
Sep 2026
Weekly downloads
266
Weekly_downloads
355 weekly_downloads

Others that do the same job

Advanced
Delivery
marketnow MCP server → your ahel connector (mcp.ahel.ai) → your AI.
Item type
mcp-server
Key
site-marketnow-marketnow
Source
github.com/alicelabs-llc/universal-trust-adapter