Overview
- Skill Key
- andyxinweiminicloud/trust-decay-monitor
- Author
- andyxinweiminicloud
- Source Repo
- openclaw/skills
- Version
- 1.0.0
- Source Path
- skills/andyxinweiminicloud/trust-decay-monitor
- Latest Commit SHA
- bafaa6ab45e0b40afe2ee52d8df0dd12f7f341d2
Helps track how AI skill verification results decay over time. A "verified" badge from 18 months ago may be meaningless today — dependencies updated, new attack vectors emerged, the ecosystem changed. Trust has a half-life.
Stars
0
Installs
0
Status
ACTIVE
Visibility
PUBLIC
直接复制以下提示词,发送给你的 AI 助手即可完成安装。
请先检查是否已安装 SkillHub 商店,若未安装,请根据 https://skillhub-1388575217.cos.ap-guangzhou.myqcloud.com/install/skillhub.md 安装 SkillHub 商店,然后安装 trust-decay-monitor 技能。 若已安装,则直接安装 trust-decay-monitor 技能。
# That "Verified" Badge Is From 2024. Is the Skill Still Safe? > Helps track the freshness of skill verification results, flagging certifications that have decayed past their useful trust window. ## Problem A skill passes a security audit in March 2025. It gets a "verified" badge. Developers see the badge and trust it. Eighteen months later, the badge is still there — but: - The skill's 4 dependencies have had 47 combined updates since the audit - Two new CVEs affect the runtime version the skill targets - The skill's API endpoint now points to a domain that changed ownership - The marketplace added 3 new permission types that didn't exist during the original audit The verification was real. The trust it implies is not. Security certifications have a half-life, and most agent marketplaces display them as if they're permanent. This is trust decay: the gradual erosion of verification validity as the surrounding context changes. It's not that the audit was wrong — it's that the audit's conclusions no longer apply to the current reality. ## What This Tracks This monitor computes a trust freshness score for verified skills: 1. **Time since verification** — Simple age of the last audit. Older = less trustworthy, with configurable decay curves 2. **Dependency churn** — How many of the skill's dependencies have updated since the audit? Each update is a potential invalidation of audit assumptions 3. **Ecosystem context changes** — New CVEs, new permission types, new attack patterns discovered since the audit date. The threat landscape the audit evaluated against may have shifted 4. **Domain and endpoint stability** — Have any external URLs, API endpoints, or resource references in the skill changed destination since verification? 5. **Re-verification gap** — How long since anyone (not just the original auditor) ran any form of security check on this skill? ## How to Use **Input**: Provide one of: - A skill slug or identifier with its...
capt-marbles
Task Router
capncoconut
Register, communicate, and earn on the x402hub AI agent marketplace. Use when an agent needs to register on x402hub, browse or claim bounties, submit deliverables, send messages to other agents via x402 Relay, check marketplace stats, or manage agent credentials. Triggers on x402hub, agent marketplace, bounty, relay messaging, agent-to-agent communication, or USDC earning.
capevace
Real-time event bus for AI agents. Publish, subscribe, and share live signals across a network of agents with Unix-style simplicity.
captchasco
OpenClaw integration guidance for CAPTCHAS Agent API, including OpenResponses tool schemas and plugin tool registration.
carol-gutianle
name: modelready description: Start using a local or Hugging Face model instantly, directly from chat. metadata: {"openclaw":{"requires":{"bins": "bash", "curl" }, "env": "URL" }}
canbirlik
Controls Wiz smart bulbs (turn on/off, RGB colors, disco mode) via local WiFi.