Mar 4, 2026 at 4:54 AM 6 signals analysed No manual reviews · fully automatedTrust Signal Breakdown high 6 sub-signals across 6 dimensions
Vulnerability & Safety ×0.25 2.5 CVEs, dependency health, and supply chain integrity
1 of 1 sub-signals with data
Operational Reliability ×0.15 3.5 Uptime, latency, error rates, and incident history
1 of 1 sub-signals with data
Maintenance Activity ×0.15 3.4 Commit recency, release cadence, issue response, CI/CD
1 of 1 sub-signals with data
Adoption ×0.15 0.6 Downloads, stars, dependents, and growth trajectory
1 of 1 sub-signals with data
Transparency ×0.15 3.0 License, documentation, security policy, changelog
1 of 1 sub-signals with data
Publisher Trust ×0.15 3.5 Track record, org maturity, community standing
1 of 1 sub-signals with data
publisher reputation 100% 3.5
About this scoreScored across 6 sub-signals in 6 dimensions Scoring engine v1 (beta) — actively being expanded Phase 1: Core sub-signal architecture (live) Phase 2: Permission scope & expanded collection (in progress)
Signal Details from signal_history
VirusTotal Scan 2.5
PENDING
ClawHub submits every skill to VirusTotal on publish. Scanned by 70+ security vendors for malware, trojans, and suspicious patterns.
Source: ClawHub moderation Content Safety 3.5
1 FINDING ⚠ credential_leak: curl\s+[^\n]*\$[A-Z_]*(?:KEY|TOKEN|SECRE
Scanned for credential leaks, shell injection, config tampering, base64 payloads, sensitive path access, SOUL.md/AGENTS.md tampering.
651 characters analyzed Publisher Reputation 3.4
Account age 9.4 years
Public repos 12
Adoption 0.6
Installs 0
Downloads 1,439
Stars 0
Comments 0
Freshness 3.0
Last updated 4d ago
Latest version v1.0.0
Versions published 1
Changelog Present
Transparency 3.5
✓ Has Changelog ✓ No Obfuscation ✓ Has Description ✓ Has Frontmatter ✓ Declares Env Vars ✓ Has Usage Instructions
Trust Assessment AI Assessment
Sure is a Skill published by bt0r under unknown license that retrieves financial reports from the Sure personal financial board application via API. The service shows low adoption (0 stars) and requires user-provided API credentials to access what appears to be a self-hosted financial management system. Connecting financial data through an unestablished service with no clear licensing presents material risk, particularly given the sensitivity of personal financial information and the requirement to expose API keys.
Generated by Fabric AI · Mar 4, 2026 at 4:54 AM
Incidents & Alerts last 90 days
Score History 5 snapshots
Feb 25 Mar 2
Are you the publisher? Claim this profile to unlock deeper evaluation, real-time monitoring, and trust signals that help agents discover your service.
Claim Provider Report Issue
Share this Trust Score Generate a scorecard image optimised for X, LinkedIn and other social platforms.
⬇ Download Score Card