MarketNow's MCP directory lists 9,248 servers, not the interceptor its HN post claims
MarketNow, run by Edison Flores's AliceLabs LLC (founded 2024, Wyoming USA), presents itself as a browse-and-install marketplace for Model Context Protocol (MCP) servers, the plug-ins that give AI agent tools such as Claude Desktop, Cursor, Cline, Continue and Aider new capabilities. The site claims a catalog of 9,248 MCP servers, searchable by category, tag or keyword and installable with a single command, npx -y @marketnow/install
Key facts
- MarketNow lists 9,248 MCP servers for tools like Claude Desktop, Cursor, Cline, Continue and Aider, installable via npx -y @marketnow/install
. - The page's pricing claims conflict: its banner and catalog link say all 9,248 listings are free, while a separate section says only 43 are free with no signup and the rest cost $0.99 to $9.99 one time, payable via Stripe or USDC on Base L2.
- The Hacker News submission title calls the site a real-time interceptor that blocks .env reads and dangerous commands, but no such feature is described anywhere on the page.
- MarketNow discloses that of its 9,248 listings, 8,742 are only auto-scanned, 22 are human-reviewed, and 0 are maintainer-verified.
- The site's own security-audit label appears as both 'Sentinel L2.5' and 'Sentinel L1.5' on the same page, without reconciling the two.
Why it matters
MCP has enough servers in circulation that a package-manager-style directory for finding and installing them, the way npm did for JavaScript packages, is a plausible next layer of the ecosystem. MarketNow's pitch, a searchable catalog with per-listing security scores and one-command installs, is a straightforward, incremental take on that need rather than a new capability.
Who it affects
Developers wiring MCP servers into Claude Desktop, Cursor, Cline, Continue, Aider or other MCP-compatible agents, who would use the catalog to find and install capabilities. It also affects developers who sell MCP servers, since the site's for-sellers pricing tiers and Stripe/USDC checkout position it as a distribution channel for them.
How to use it
Servers are found by browsing 9,248 listings by category, tag, keyword, price or security score, then installed with npx -y @marketnow/install
How solid is it
The central discrepancy is that the Hacker News submission title, 'Real-time MCP interceptor that blocks .env reads and dangerous commands agents,' describes functionality that does not appear anywhere on the page: no interceptor, no runtime blocking, no .env protection is documented. What the page actually describes is a browse, pay and install marketplace. Separately, MarketNow's own disclosures temper its security claims: of the 9,248 listed servers, 8,742 are only auto-scanned with no human review, 22 are human-reviewed, and 0 are maintainer-verified, and its 'Sentinel' audit label is given as both L2.5 and L1.5 in different parts of the same page without explanation. The company is a solo operation, founded in 2024 by Edison Flores with no investors, no employees beyond the founder, and no marketing budget.
Risks and caveats
The gap between the HN title's interceptor framing and the marketplace the page actually describes means anyone arriving expecting a runtime security tool will not find one there. The vast majority of listed servers, 8,742 of 9,248, carry only an automated scan with no human review, so the presence of a 'Sentinel' score does not by itself indicate a person checked the code. The site gives no figures for how many users, downloads or how much revenue it has, no timeframe for how the catalog reached its current size, and no explanation of how the 'real GitHub stars, real npm downloads' numbers shown per listing are verified or kept current.