MarketNow
Trust Layer for Agent Commerce
Discovery is solved (MCP registry, Smithery, Glama). Trust is not.
MarketNow is the trust layer — every skill Sentinel-scanned, every payment verified on-chain, every mandate human-approved by default.
Sentinel L2 Security
Real-time audit on every API call
L1.5 LIVE 6 metadata checks: AUTH, prompt injection, input validation, CORS, OAuth, rate limiting
L1.6 LIVE Code analysis: 18 secret patterns, 18 MCP prompt injection rules, OSV API dependency check, hygiene
L2 LIVE Behavioral: fetches actual source code from GitHub, analyzes 16 runtime patterns (network, filesystem, process, credential, exfiltration, dynamic imports)
All in ONE endpoint, ONE call, real-time. No Docker needed.
How It Works
Agent purchase flow (x402)
AP2 Mandates
Human-in-the-loop by default
✅ Default: notify — human gets email/webhook alert on every purchase
✅ 3 autonomous purchases — agent can buy without per-purchase approval
✅ After 3: requires_reapproval — human must re-approve
✅ Hard caps: $500 total, $50 per purchase, 90-day expiry
✅ Every spend = public git commit at _data/mandates/
Balances agent autonomy with LLM provider safety policies.
10 AliceLabs Security Tools
Original, human-reviewed, $2.99-$9.99
Prompt injection firewall
MCP server firewall + audit
RAG pipeline security
GDPR/EU AI Act compliance
Offensive LLM pentesting
Memory poisoning defense
Honest Transparency
What we admit we don't have yet
PARTIAL Third-party audit — paid audits deferred until revenue. Volunteer peer review open.
DONE Catalog transparency — 14 bulk-imported categories disclosed, 0 synthetic skills
DONE Human-in-loop by default — not "no humans needed"
PARTIAL Payment reversibility — manual dispute process, on-chain escrow on roadmap Q1 2027
Every status is a git commit. See /trust for the full roadmap.
Try It Now
marketnow.site
AliceLabs LLC — Wyoming, USA · 2025
Bootstrapped · No investors · Built in public