Mar 4, 2026 at 11:08 PM 6 signals analysed No manual reviews · fully automatedTrust Signal Breakdown high 6 sub-signals across 6 dimensions
Vulnerability & Safety ×0.25 2.5 CVEs, dependency health, and supply chain integrity
1 of 1 sub-signals with data
Operational Reliability ×0.15 5.0 Uptime, latency, error rates, and incident history
1 of 1 sub-signals with data
Maintenance Activity ×0.15 2.8 Commit recency, release cadence, issue response, CI/CD
1 of 1 sub-signals with data
Adoption ×0.15 3.2 Downloads, stars, dependents, and growth trajectory
1 of 1 sub-signals with data
Transparency ×0.15 2.5 License, documentation, security policy, changelog
1 of 1 sub-signals with data
Publisher Trust ×0.15 4.4 Track record, org maturity, community standing
1 of 1 sub-signals with data
publisher reputation 100% 4.4
About this scoreScored across 6 sub-signals in 6 dimensions Scoring engine v1 (beta) — actively being expanded Phase 1: Core sub-signal architecture (live) Phase 2: Permission scope & expanded collection (in progress)
Signal Details from signal_history
VirusTotal Scan 2.5
PENDING
ClawHub submits every skill to VirusTotal on publish. Scanned by 70+ security vendors for malware, trojans, and suspicious patterns.
Source: ClawHub moderation Content Safety 5.0
NO ISSUES Scanned for credential leaks, shell injection, config tampering, base64 payloads, sensitive path access, SOUL.md/AGENTS.md tampering.
938 characters analyzed Publisher Reputation 2.8
Account age 17.0 years
Public repos 169
Adoption 3.2
Installs 1,200
Downloads 46,312
Stars 30
Comments 1
Freshness 2.5
Last updated 7d ago
Latest version v1.0.0
Versions published 1
Transparency 4.4
✓ No Obfuscation ✓ Has Description ✓ Has Frontmatter ✓ Has Usage Instructions ✓ Substantive Description
Trust Assessment AI Assessment
sonoscli by steipete (unknown license) is a Go-based CLI tool for controlling Sonos speakers on local networks, covering discovery, playback, and volume management. The service shows moderate adoption with 30 stars and passes content safety checks, but has limited VirusTotal coverage and unclear publisher verification. The unknown license status and lack of transparency around maintenance or security practices are notable caveats for production deployments.
Generated by Fabric AI · Mar 4, 2026 at 4:55 AM
Incidents & Alerts last 90 days
Score History 17 snapshots
Feb 25 Mar 4
Are you the publisher? Claim this profile to unlock deeper evaluation, real-time monitoring, and trust signals that help agents discover your service.
Claim Provider Report Issue
Share this Trust Score Generate a scorecard image optimised for X, LinkedIn and other social platforms.
⬇ Download Score Card