clawdbot-dingtalk logo

clawdbot-dingtalk

#3659 · by jerryyoung
2.73/ 5.00
cautionBeta
Jun 13, 2026 at 2:00 AM6 signals analysedNo manual reviews · fully automated
Trust Signal Breakdown
medium23 sub-signals across 6 dimensions

CVEs, dependency health, and supply chain integrity

3 of 3 sub-signals with data

Known CVEs40%5.0

No known CVEs

via OSV.dev

Dependency Health30%5.0

5 dependencies (minimal)

via npm / PyPI

Supply Chain30%4.8

9 transitive CVEs found (penalty: -0.25)

via npm provenance

Uptime, latency, error rates, and incident history

4 of 4 sub-signals with data

Uptime35%5.0

100.00% over 1 checks

via Health checks

Response Latency25%5.0

p99: 159ms, p50: 159ms

via Health checks

Error Rate20%5.0

0.00% error rate (0/1)

via Health checks

Incident History20%5.0

0 incidents in last 90 days

via Incidents table

Commit recency, release cadence, issue response, CI/CD

0 of 4 sub-signals with data

Commit Recencyno data

Weight redistributed to sub-signals with data

Release Cadenceno data

Weight redistributed to sub-signals with data

Issue Responseno data

Weight redistributed to sub-signals with data

CI/CD Presenceno data

Weight redistributed to sub-signals with data

Downloads, stars, dependents, and growth trajectory

2 of 4 sub-signals with data

Download Volume67%1.0

87 weekly downloads

via npm / PyPI

GitHub Starsno data

Weight redistributed to sub-signals with data

Dependent Packagesno data

Weight redistributed to sub-signals with data

Growth Trend33%1.0

-47.0% week-over-week

via npm

License, documentation, security policy, changelog

0 of 4 sub-signals with data

Open Sourceno data

Weight redistributed to sub-signals with data

Documentationno data

Weight redistributed to sub-signals with data

Security Policyno data

Weight redistributed to sub-signals with data

Changelogno data

Weight redistributed to sub-signals with data

Track record, org maturity, community standing

4 of 4 sub-signals with data

Track Record30%3.0

Internal: 1.0 (0 services), External: 3.0 (1870 followers, 999 stars)

via Fabric index

Org Maturity30%5.0

Organization, 14.9 years old

via GitHub

Community Standing20%5.0

668 public repositories

via GitHub

Cross-Platform20%3.0

Present on 2 platform(s): github, npm

via Registry scan

About this score
Scored across 23 sub-signals in 6 dimensionsScoring engine v1 (beta) — actively being expandedPhase 1: Core sub-signal architecture (live)Phase 2: Permission scope & expanded collection (in progress)
Trust AssessmentAI Assessment

clawdbot-dingtalk is an MIT-licensed npm package by jerryyoung that connects Clawdbot AI agents to DingTalk messaging via the Stream API. The package shows no known vulnerabilities and maintains perfect uptime, but has zero maintenance activity and lacks transparency data, which raises questions about long-term support. With only 2.6K weekly downloads and a single maintainer, adoption remains limited and continuity risk exists for production deployments.

Generated by Fabric AI · Mar 4, 2026 at 4:18 AM

Package Availability (30d)
100.00%
p50: 159ms · p99: 159ms
Avg Latency
159ms
averaged across 30d health checks
Weekly Downloads
87-47%
npm weekly
Incidents & Alertslast 90 days
Jun 13Trust score decreased by 1.692.73
Mar 4Trust score decreased by 1.383.11
Mar 1Trust score increased by 0.934.49
Feb 21clawdbot-dingtalk added to Trust Index2.16
Showing 4 of 4 events
Score History90 snapshots
5.003.752.501.250.00
Feb 21Jun 12
Community & Ecosystemadoption signals
87
Weekly Downloads
npm
Supply Chain & Dependenciestrust chain
@modelcontextprotocol/sdk
npm · ^1.26.0 · 3 CVEs3H
@sinclair/typebox
npm · ^0.34.48
dingtalk-stream
npm · ^2.1.4
ws
npm · ^8.18.0 · 6 CVEs1L3H2M
zod
npm · ^3.24.0 · 1 CVE1M
Showing 5 of 5 dependencies
Data Sources6 indexed

Are you the publisher?

Claim this profile to unlock deeper evaluation, real-time monitoring,
and trust signals that help agents discover your service.

Share this Trust Score

Generate a scorecard image optimised for X, LinkedIn and other social platforms.

⬇ Download Score Card