MarketNow's MCP directory lists 9,248 servers, not the interceptor its HN post claims

MarketNow, run by Edison Flores's AliceLabs LLC (founded 2024, Wyoming USA), presents itself as a browse-and-install marketplace for Model Context Protocol (MCP) servers, the plug-ins that give AI agent tools such as Claude Desktop, Cursor, Cline, Continue and Aider new capabilities. The site claims a catalog of 9,248 MCP servers, searchable by category, tag or keyword and installable with a single command, npx -y @marketnow/install . The page gives conflicting figures on price: its opening banner and free-skills catalog link both claim all 9,248 listings are free, while a separate pricing section says only 43 of the 9,248 listings are free with no payment or signup and the rest cost $0.99 to $9.99 as one-time purchases, payable by credit card through Stripe or in USDC on Base L2, without reconciling the two claims. The Hacker News submission for the site was titled 'Real-time MCP interceptor that blocks .env reads and dangerous commands agents,' but the page contains no description of any such interceptor, runtime blocking, .env protection, or dangerous-command blocking; it documents a marketplace for finding, paying for and installing MCP servers, not a tool that intercepts an agent's actions at runtime. The site markets its listings as 'Sentinel' security-audited, describing a 6-point audit run over a gVisor sandbox, though the opening banner labels this system 'Sentinel L2.5' while a later section on the same page calls it 'Sentinel L1.5,' without explaining the discrepancy. MarketNow's own review-status disclosure states that of the 9,248 catalog entries, 8,742 are auto-scanned only with no human review, 22 are human-reviewed, and 0 are maintainer-verified because that program has not launched. The company describes itself as having no investors, no employees besides Flores, and no marketing budget, and says its agent-facing purchase API defaults to notifying the buyer (the 'principal') on every transaction, with silent purchases requiring an explicit opt-in.

Key facts

  • MarketNow lists 9,248 MCP servers for tools like Claude Desktop, Cursor, Cline, Continue and Aider, installable via npx -y @marketnow/install .
  • The page's pricing claims conflict: its banner and catalog link say all 9,248 listings are free, while a separate section says only 43 are free with no signup and the rest cost $0.99 to $9.99 one time, payable via Stripe or USDC on Base L2.
  • The Hacker News submission title calls the site a real-time interceptor that blocks .env reads and dangerous commands, but no such feature is described anywhere on the page.
  • MarketNow discloses that of its 9,248 listings, 8,742 are only auto-scanned, 22 are human-reviewed, and 0 are maintainer-verified.
  • The site's own security-audit label appears as both 'Sentinel L2.5' and 'Sentinel L1.5' on the same page, without reconciling the two.

Why it matters

MCP has enough servers in circulation that a package-manager-style directory for finding and installing them, the way npm did for JavaScript packages, is a plausible next layer of the ecosystem. MarketNow's pitch, a searchable catalog with per-listing security scores and one-command installs, is a straightforward, incremental take on that need rather than a new capability.

Who it affects

Developers wiring MCP servers into Claude Desktop, Cursor, Cline, Continue, Aider or other MCP-compatible agents, who would use the catalog to find and install capabilities. It also affects developers who sell MCP servers, since the site's for-sellers pricing tiers and Stripe/USDC checkout position it as a distribution channel for them.

How to use it

Servers are found by browsing 9,248 listings by category, tag, keyword, price or security score, then installed with npx -y @marketnow/install . The page's pricing claims conflict: its banner and catalog link say all 9,248 listings are free, while a separate section says forty-three listings are free with no signup and the rest are $0.99 to $9.99 one-time purchases via Stripe (with chargeback rights) or USDC on Base L2. The site also exposes itself as an MCP server, npx -y marketnow-mcp, available on npm and Smithery, plus a public JSON API for agents including a full catalog endpoint, search, and a purchase endpoint supporting five transaction modes.

How solid is it

The central discrepancy is that the Hacker News submission title, 'Real-time MCP interceptor that blocks .env reads and dangerous commands agents,' describes functionality that does not appear anywhere on the page: no interceptor, no runtime blocking, no .env protection is documented. What the page actually describes is a browse, pay and install marketplace. Separately, MarketNow's own disclosures temper its security claims: of the 9,248 listed servers, 8,742 are only auto-scanned with no human review, 22 are human-reviewed, and 0 are maintainer-verified, and its 'Sentinel' audit label is given as both L2.5 and L1.5 in different parts of the same page without explanation. The company is a solo operation, founded in 2024 by Edison Flores with no investors, no employees beyond the founder, and no marketing budget.

Risks and caveats

The gap between the HN title's interceptor framing and the marketplace the page actually describes means anyone arriving expecting a runtime security tool will not find one there. The vast majority of listed servers, 8,742 of 9,248, carry only an automated scan with no human review, so the presence of a 'Sentinel' score does not by itself indicate a person checked the code. The site gives no figures for how many users, downloads or how much revenue it has, no timeframe for how the catalog reached its current size, and no explanation of how the 'real GitHub stars, real npm downloads' numbers shown per listing are verified or kept current.