Score capped to 2.99 (raw score: 3.16) due to insufficient data in one or more signals. The composite is held at caution level until all signals can be fully evaluated.
Jun 12, 2026 at 11:03 AM6 signals analysedNo manual reviews · fully automated
Trust Signal Breakdown
medium23 sub-signals across 6 dimensions
CVEs, dependency health, and supply chain integrity
0 of 3 sub-signals with data
Known CVEsno data—
Weight redistributed to sub-signals with data
Dependency Healthno data—
Weight redistributed to sub-signals with data
Supply Chainno data—
Weight redistributed to sub-signals with data
Uptime, latency, error rates, and incident history
Public repo with OSI-approved license (apache-2.0)
via GitHub
Documentation25%4.0
Good README (>2000 bytes with examples)
via GitHub
Security Policy20%2.0
No SECURITY.md found
via GitHub
Changelog25%5.0
CHANGELOG.md present and releases exist
via GitHub
Track record, org maturity, community standing
0 of 4 sub-signals with data
Track Recordno data—
Weight redistributed to sub-signals with data
Org Maturityno data—
Weight redistributed to sub-signals with data
Community Standingno data—
Weight redistributed to sub-signals with data
Cross-Platformno data—
Weight redistributed to sub-signals with data
About this score
Scored across 23 sub-signals in 6 dimensionsScoring engine v1 (beta) — actively being expandedPhase 1: Core sub-signal architecture (live)Phase 2: Permission scope & expanded collection (in progress)
Trust AssessmentAI Assessment
AI agent security scanner — 7 tools to detect prompt injection, SQL injection, PII exposure, and data exfiltration. 9-layer detection pipeline with optional LLM analysis.