Mar 4, 2026 at 4:18 AM 6 signals analysed No manual reviews · fully automatedTrust Signal Breakdown high 6 sub-signals across 6 dimensions
Vulnerability & Safety ×0.25 2.5 CVEs, dependency health, and supply chain integrity
1 of 1 sub-signals with data
Operational Reliability ×0.15 5.0 Uptime, latency, error rates, and incident history
1 of 1 sub-signals with data
Maintenance Activity ×0.15 3.4 Commit recency, release cadence, issue response, CI/CD
1 of 1 sub-signals with data
Adoption ×0.15 0.6 Downloads, stars, dependents, and growth trajectory
1 of 1 sub-signals with data
Transparency ×0.15 3.0 License, documentation, security policy, changelog
1 of 1 sub-signals with data
Publisher Trust ×0.15 2.6 Track record, org maturity, community standing
1 of 1 sub-signals with data
publisher reputation 100% 2.6
About this scoreScored across 6 sub-signals in 6 dimensions Scoring engine v1 (beta) — actively being expanded Phase 1: Core sub-signal architecture (live) Phase 2: Permission scope & expanded collection (in progress)
Signal Details from signal_history
VirusTotal Scan 2.5
PENDING
ClawHub submits every skill to VirusTotal on publish. Scanned by 70+ security vendors for malware, trojans, and suspicious patterns.
Source: ClawHub moderation Content Safety 5.0
NO ISSUES Scanned for credential leaks, shell injection, config tampering, base64 payloads, sensitive path access, SOUL.md/AGENTS.md tampering.
1,094 characters analyzed Publisher Reputation 3.4
Account age 4.9 years
Public repos 15
Adoption 0.6
Installs 1
Downloads 2,585
Stars 2
Comments 0
Freshness 3.0
Last updated 4d ago
Latest version v1.0.0
Versions published 1
Changelog Present
Transparency 2.6
✓ Has Changelog ✓ No Obfuscation ✓ Has Description ✓ Has Frontmatter ✓ Has Usage Instructions ✓ Substantive Description
Trust Assessment AI Assessment
win-mouse-native is a Windows mouse automation skill published by lurklight on clawhub under an unknown license, providing native pointer control through user32.dll. The service shows clean content safety but has a low VirusTotal signal (2.50/5.00) and minimal adoption (2 stars), indicating limited community validation. The unknown license and requirement to manually convert text files to executable scripts (`.cmd` and `.ps1`) present deployment and provenance risks typical of unverified automation tools.
Generated by Fabric AI · Mar 4, 2026 at 4:18 AM
Incidents & Alerts last 90 days
Score History 4 snapshots
Feb 25 Mar 2
Are you the publisher? Claim this profile to unlock deeper evaluation, real-time monitoring, and trust signals that help agents discover your service.
Claim Provider Report Issue
Share this Trust Score Generate a scorecard image optimised for X, LinkedIn and other social platforms.
⬇ Download Score Card