3.51/ 5.00
trustedBeta
Mar 4, 2026 at 11:08 PM6 signals analysedNo manual reviews · fully automated
Trust Signal Breakdown
high6 sub-signals across 6 dimensions

CVEs, dependency health, and supply chain integrity

1 of 1 sub-signals with data

virustotal scan100%2.5

Uptime, latency, error rates, and incident history

1 of 1 sub-signals with data

content safety100%5.0

Commit recency, release cadence, issue response, CI/CD

1 of 1 sub-signals with data

freshness100%2.8

Downloads, stars, dependents, and growth trajectory

1 of 1 sub-signals with data

adoption100%3.2

License, documentation, security policy, changelog

1 of 1 sub-signals with data

transparency100%2.5

Track record, org maturity, community standing

1 of 1 sub-signals with data

publisher reputation100%4.4
About this score
Scored across 6 sub-signals in 6 dimensionsScoring engine v1 (beta) — actively being expandedPhase 1: Core sub-signal architecture (live)Phase 2: Permission scope & expanded collection (in progress)
Signal Detailsfrom signal_history
VirusTotal Scan2.5
PENDING

ClawHub submits every skill to VirusTotal on publish. Scanned by 70+ security vendors for malware, trojans, and suspicious patterns.

Source: ClawHub moderation
Content Safety5.0
NO ISSUES

Scanned for credential leaks, shell injection, config tampering, base64 payloads, sensitive path access, SOUL.md/AGENTS.md tampering.

938 characters analyzed
Publisher Reputation2.8
GitHubsteipete
Account age17.0 years
Public repos169
Adoption3.2
Installs1,200
Downloads46,312
Stars30
Comments1
Freshness2.5
Last updated7d ago
Latest versionv1.0.0
Versions published1
Transparency4.4
5/5 checks passed100%
No Obfuscation Has Description Has Frontmatter Has Usage Instructions Substantive Description
Trust AssessmentAI Assessment

sonoscli by steipete (unknown license) is a Go-based CLI tool for controlling Sonos speakers on local networks, covering discovery, playback, and volume management. The service shows moderate adoption with 30 stars and passes content safety checks, but has limited VirusTotal coverage and unclear publisher verification. The unknown license status and lack of transparency around maintenance or security practices are notable caveats for production deployments.

Generated by Fabric AI · Mar 4, 2026 at 4:55 AM

Incidents & Alertslast 90 days
Feb 25sonoscli added to Trust Index3.44
Showing 1 of 1 events
Score History17 snapshots
5.003.752.501.250.00
Feb 25Mar 4
Data Sources4 indexed

Are you the publisher?

Claim this profile to unlock deeper evaluation, real-time monitoring,
and trust signals that help agents discover your service.

Share this Trust Score

Generate a scorecard image optimised for X, LinkedIn and other social platforms.

⬇ Download Score Card