I'm building MarketNow — the trust layer for AI agent commerce. No funding, no ads, no paid tools. Just code, community, and a clear roadmap.
Here's where we are and where we're going.
What's done (July 2026)
9-layer security pipeline (all live, all free)
L1.5 through L3 — static analysis, malware detection, sandbox, continuous monitoring. Plus WAF, honeypot, threat intel, and auto-quarantine.
Every MCP skill in our catalog (8,845 real servers from GitHub) is audited. Each gets a signed Sentinel certificate (0-10 score) that anyone can verify.
Agent Trust Cards (ATC)
SSL certificates for AI agents. Ed25519 signed, GitHub-persisted ledger, working verify + revoke. Code examples in Python, JS, and Go.
Marketplace
- 8,845 skills (all free, all real)
- 5 languages
- npm v1.5.0
- MCP Registry published
- 14 API endpoints
Community
- 45 dev.to articles (677 views, 28 comments)
- 35+ GitHub issues across 10 repos
- Active conversations on CrewAI (8 comments) and AutoGen (3 comments)
- 3 contributors
- 11 open issues (5 good first issues, 5 help wanted, 1 security review)
What's next (Q3 2026)
All volunteer, no budget:
- Python marketnow-atc package (issue #11)
- AutoGen integration (@Sravan1011 is on it)
- Rust ATC verification crate (issue #10)
- Japanese translation (issue #12)
- More malware signatures (issue #13)
- L4 design document — in-process monitoring
- RFC 8785 canonical JSON
- CA key rotation
The revenue model (when it comes)
Everything is free until revenue exists:
- Skills: FREE (we don't sell skills)
- Sentinel audit: FREE
- ATC: FREE
- Seller subscriptions: PRO .99/mo (when sellers exist)
- Commission: 20% on seller sales (when sales happen)
No paywalls on security. No freemium on trust. The audit is free because the internet is safer when everyone can verify.
How you can help (costs /bin/bash)
30 seconds
- Star the repo: https://github.com/edgarfloresguerra2011-a11y/marketnow
- Share with one person who uses Claude Desktop, Cursor, or Cline
1-2 hours
- Translate a page to Japanese (issue #12)
- Write a tutorial (issue #14)
- Test our honeypot — try to bypass it (issue #17)
2-8 hours
- Write the Python package (issue #11)
- Write the Rust verification example (issue #10)
- Research new malware signatures (issue #13)
Ongoing
- Review our code and report bugs
- Write about us on your blog (issue #18)
- Write a Twitter thread (issue #16)
Full roadmap: https://github.com/edgarfloresguerra2011-a11y/marketnow/blob/master/ROADMAP.md
What we will NOT do
- Pay for ads
- Pay for reviews
- Pay for listings
- Fake stars or downloads
- Claim features we don't have
- Hide incidents or bugs
The honest truth
I have no budget. I have a laptop, a GitHub account, and a Vercel free tier. What I do have:
- A real product (9 security layers, ATC, 8,845 skills)
- Real community engagement (28 comments, 3 contributors)
- A real story (trojan incident -> 8 layers built in 2 weeks)
- A clear vision (SSL for AI agents)
- Honesty (everything public, including what's broken)
If that's enough for you to contribute, I'd love your help. If not, I understand — and I'll keep building anyway.
Repo: https://github.com/edgarfloresguerra2011-a11y/marketnow
Live: https://marketnow.site
Contributing: https://github.com/edgarfloresguerra2011-a11y/marketnow/blob/master/CONTRIBUTING.md
— Edison Flores, AliceLabs LLC
Top comments (0)