Security evidence matrix

Every layer MarketNow's agent declares → the public artifact where you verify it · generated 2026-09-25

9 live 1 partial (declared) Machine version: /api/security

The agent profile (agent.json) declares a 10-layer audit pipeline. This page exists so that claim is checkable: each row links the layer to a live endpoint, a repo file, or a signed record. Where a layer is partial or planned, the row says so — that is the point of the page.

10
declared layers (L1→L3 + L4–L9 grouped)
68,388
L1-certified entries · 10 checks · 9 fully green
2,839
tarballs deep-scanned (29 rules)
0.857
benchmark F1 (decision level, n=18)

Layer → evidence

LayerWhat it doesStatusLive numbersVerify at
L1Index certification — 10 checks recomputed over the live bundle (unique ids/slugs, required fields, risk model, price consistency, provenance URL).live 68,388 certified · C4: 4 documented exceptions (provenance unknown, url=null) /api/certification.json/api/stats.json
L1.5Metadata static checks — auth, injection hints, validation, CORS, OAuth, rate-limit — on every real-time audit call.live 6 checks · ~200ms per call /api/audit-skill?skillId=…
L1.6Semgrep-equivalent rules + secret patterns + OSV dependency check (real-time + weekly batch).live 18 + 18 rules · batch: 1,257 secret findings, 1 OSV vuln (own repo) /api/audit-skill?sentinel-status=1
L1.7Binary & malware detection: nested archives, PE executables, launchers. Born from the July trojan incident.live 1 documented catch (issue #9) · regression vector embedded lib/sentinel-l17.mjs (repo)
L1.8Malware family signatures (YARA-class; Win64/Lazy.PGPK staged launcher).live backstop role · 0 catches beyond L1.7 lib/sentinel-l18.mjs (repo)
L1.9Prompt-injection firewall over descriptions and system prompts.live 1 public catch (ledger qd_2026_08_15_001) /api/quarantine (ledger)
L2Deep scan of shipped npm tarballs: download, shasum-verify, 29 rules in tarball mode (dist/ included — the code that runs).live 2,839 / 2,868 targets (99%) · 885 clean · 791 warn · 1,156 error · 5.59M weekly dl covered /api/certification-scans.json/api/certification?summary=1
L2.5Sandbox execution: Docker --network none + seccomp + cap-drop ALL (GitHub Actions, async). gVisor: planned v3.1.partial 1 runtime catch (trojan via clone() denial) /security/sentinel-v3.0 (config)
L3Runtime monitoring & drift: tool-catalog drift detection, revocation registry (CRL + OCSP), interceptor policy manifest.live 6 interceptor rules · CRL/OCSP endpoints live /api/interceptor.json/api/crl/api/ocsp
L4–L9Dependency scan (OSV), secret patterns, family signatures, SBOM (SPDX 2.3), interceptor policy, post-execution filter.live OSV: 0 vulnerabilities / 688 locked deps · OWASP MCP cheat-sheet matrix /api/owasp.jsonCI workflows (repo)

Decision evidence

ClaimWhere to verify
Quarantine ledger — tamper-evident, SHA-256 per record, auditable FP/FN rate over time/api/quarantine
Sentinel benchmark — precision 0.75 · recall 1.00 · F1 0.857 (n=18, all inputs public)/security/sentinel-benchmark
Independent pentest — NOT performed yet; scope published, compensating controls live/security/audit-2026-08-19#pentest
Current audit state — AUD-2026-0925 supersedes AUD-2026-0821-MN; re-audit 2026-12-25/trust/audit-status.json
766,211 security checks performed = 683,880 L1 (10 × 68,388) + 82,331 L2 (29 × 2,839) — breakdown in agent.json/api/agent.json
Taxonomy — Sentinel 12 stages / 10 layers; ATC/1.0 10 controls (8 required); UTA 9 adapters/security/sentinel-v3.0
CA incident 2026-09-08 — mn-ca-002 revoked (KEY_COMPROMISE), fail-closed, 4 Rekor anchors/security/incidents/2026-09-08
License matrix — every component, one table, registry-verifiable/licensing
MCP tools — remote endpoint 9 discovery/trust tools; npm package 15 local tools (different by design)/.well-known/mcp.json

What this matrix does not claim

Honesty notes.