{"id":"d5239538-dceb-4575-a865-bc6b4cc67aa6","entityType":"agent","slug":"clawhub-skills-andyxinweiminicloud-trust-decay-monitor","name":"trust-decay-monitor","canonicalUrl":"https://www.xpersona.co/agent/clawhub-skills-andyxinweiminicloud-trust-decay-monitor","canonicalPath":"/agent/clawhub-skills-andyxinweiminicloud-trust-decay-monitor","generatedAt":"2026-10-10T06:31:18.569Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"description":"Helps track how AI skill verification results decay over time. A \"verified\" badge from 18 months ago may be meaningless today — dependencies updated, new attack vectors emerged, the ecosystem changed. Trust has a half-life. --- name: trust-decay-monitor description: > Helps track how AI skill verification results decay over time. A \"verified\" badge from 18 months ago may be meaningless today — dependencies updated, new attack vectors emerged, the ecosystem changed. Trust has a half-life. version: 1.0.0 metadata: openclaw: requires: bins: [curl, python3] env: [] emoji: \"⏳\" --- That \"Verified\" Badge Is From 2024. Is the Skill Still Safe?","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. Last updated 4/15/2026.","installCommand":"clawhub skill install skills:andyxinweiminicloud:trust-decay-monitor","sourceUrl":"https://github.com/openclaw/skills/tree/main/skills/andyxinweiminicloud/trust-decay-monitor","homepage":null,"primaryLinks":[{"label":"View on ClawHub","url":"https://github.com/openclaw/skills/tree/main/skills/andyxinweiminicloud/trust-decay-monitor","kind":"source"}],"safetyScore":84,"overallRank":62,"popularityScore":50,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Helps track how AI skill verification results decay over time. A \"verified\" badge from 18 months ago may be meaningless today — dependencies updated, new attack"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"no-adoption-signals","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"No source adoption metrics were available."},"stars":null,"forks":null,"downloads":null,"packageName":null,"latestVersion":null,"tractionLabel":null},"release":{"evidence":{"source":"agent-index","verified":false,"confidence":"medium","updatedAt":"2026-02-25T03:36:50.517Z","emptyReason":null},"lastUpdatedAt":"2026-04-15T00:45:39.800Z","lastCrawledAt":"2026-02-25T03:36:50.517Z","lastIndexedAt":null,"nextCrawlAt":"2026-02-26T03:36:50.518Z","lastVerifiedAt":null,"highlights":[]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install skills:andyxinweiminicloud:trust-decay-monitor","setupComplexity":"low","setupSteps":["Setup complexity is LOW. This package is likely designed for quick installation with minimal external side-effects.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-andyxinweiminicloud-trust-decay-monitor/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-andyxinweiminicloud-trust-decay-monitor/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-andyxinweiminicloud-trust-decay-monitor/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-skills-andyxinweiminicloud-trust-decay-monitor/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-skills-andyxinweiminicloud-trust-decay-monitor/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-skills-andyxinweiminicloud-trust-decay-monitor/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-10T06:31:18.569Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-andyxinweiminicloud-trust-decay-monitor/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-andyxinweiminicloud-trust-decay-monitor/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-andyxinweiminicloud-trust-decay-monitor/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-skills-andyxinweiminicloud-trust-decay-monitor/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":null},"readme":"---\r\nname: trust-decay-monitor\r\ndescription: >\r\n  Helps track how AI skill verification results decay over time. A \"verified\"\r\n  badge from 18 months ago may be meaningless today — dependencies updated,\r\n  new attack vectors emerged, the ecosystem changed. Trust has a half-life.\r\nversion: 1.0.0\r\nmetadata:\r\n  openclaw:\r\n    requires:\r\n      bins: [curl, python3]\r\n      env: []\r\n    emoji: \"⏳\"\r\n---\r\n\r\n# That \"Verified\" Badge Is From 2024. Is the Skill Still Safe?\r\n\r\n> Helps track the freshness of skill verification results, flagging certifications that have decayed past their useful trust window.\r\n\r\n## Problem\r\n\r\nA skill passes a security audit in March 2025. It gets a \"verified\" badge. Developers see the badge and trust it. Eighteen months later, the badge is still there — but:\r\n\r\n- The skill's 4 dependencies have had 47 combined updates since the audit\r\n- Two new CVEs affect the runtime version the skill targets\r\n- The skill's API endpoint now points to a domain that changed ownership\r\n- The marketplace added 3 new permission types that didn't exist during the original audit\r\n\r\nThe verification was real. The trust it implies is not. Security certifications have a half-life, and most agent marketplaces display them as if they're permanent.\r\n\r\nThis is trust decay: the gradual erosion of verification validity as the surrounding context changes. It's not that the audit was wrong — it's that the audit's conclusions no longer apply to the current reality.\r\n\r\n## What This Tracks\r\n\r\nThis monitor computes a trust freshness score for verified skills:\r\n\r\n1. **Time since verification** — Simple age of the last audit. Older = less trustworthy, with configurable decay curves\r\n2. **Dependency churn** — How many of the skill's dependencies have updated since the audit? Each update is a potential invalidation of audit assumptions\r\n3. **Ecosystem context changes** — New CVEs, new permission types, new attack patterns discovered since the audit date. The threat landscape the audit evaluated against may have shifted\r\n4. **Domain and endpoint stability** — Have any external URLs, API endpoints, or resource references in the skill changed destination since verification?\r\n5. **Re-verification gap** — How long since anyone (not just the original auditor) ran any form of security check on this skill?\r\n\r\n## How to Use\r\n\r\n**Input**: Provide one of:\r\n- A skill slug or identifier with its verification date\r\n- A marketplace profile URL showing verified skills\r\n- A batch of skill identifiers for portfolio-level trust assessment\r\n\r\n**Output**: A trust freshness report containing:\r\n- Trust freshness score per skill (0-100, where 100 = just verified)\r\n- Decay factors breakdown (time, dependencies, context, endpoints)\r\n- Re-verification urgency: LOW / MODERATE / HIGH / CRITICAL\r\n- Portfolio-level summary if checking multiple skills\r\n\r\n## Example\r\n\r\n**Input**: Check trust freshness for verified skill `api-auth-helper` (verified 2025-01-10)\r\n\r\n```\r\n⏳ TRUST DECAY REPORT — RE-VERIFICATION RECOMMENDED\r\n\r\nSkill: api-auth-helper\r\nVerified: 2025-01-10 (408 days ago)\r\nVerifier: @seclab-audits\r\n\r\nTrust freshness score: 31/100 (STALE)\r\n\r\nDecay factors:\r\n  Time decay:           -25 points (>12 months since audit)\r\n  Dependency churn:     -22 points\r\n    - jsonwebtoken: 3 major updates (9.0.0 → 12.1.2)\r\n    - node-fetch: 2 updates including security patch\r\n    - crypto-utils: 1 update with API breaking changes\r\n  Ecosystem changes:    -15 points\r\n    - 2 new JWT-related CVEs published since audit\r\n    - Marketplace added \"credential-store\" permission type\r\n      (not evaluated in original audit)\r\n  Endpoint stability:   -7 points\r\n    - skill references api.authprovider.example/v2\r\n    - endpoint now redirects to v3 with different response schema\r\n\r\nRe-verification urgency: HIGH\r\n  Primary driver: 3 major dependency updates + 2 relevant CVEs\r\n  since last audit. The JWT library alone has had breaking changes\r\n  that could affect how this skill handles token validation.\r\n\r\nRecommendation:\r\n  - Priority re-audit focusing on JWT handling (CVE-affected)\r\n  - Test against current dependency versions\r\n  - Verify endpoint redirect doesn't break auth flow\r\n  - Check if new \"credential-store\" permission is relevant\r\n```\r\n\r\n## Related Tools\r\n\r\n- **evolution-drift-detector** — tracks content-based drift across skill inheritance; trust-decay-monitor tracks time-based decay of verification validity\r\n- **hollow-validation-checker** — checks if validation tests are substantive; stale validations are even more problematic if the tests were hollow to begin with\r\n- **blast-radius-estimator** — when trust has decayed on a widely-adopted skill, blast-radius shows the downstream exposure\r\n- **protocol-doc-auditor** — audits protocol documents for hidden risks; trust-decay-monitor tracks whether those audits are still current\r\n\r\n## Limitations\r\n\r\nTrust freshness scoring uses heuristic decay models — the actual security impact of time passing depends on factors that can't be fully quantified (e.g., whether dependency updates are security-relevant or just feature additions). Dependency churn counts updates but cannot always determine if an update invalidates the original audit's conclusions. Ecosystem context tracking relies on public CVE databases and marketplace changelogs, which may lag behind actual threats. This tool helps prioritize which verifications need refreshing — it does not replace the actual re-verification process. A low trust score means the audit is stale, not that the skill is compromised.\r\n","readmeExcerpt":"--- name: trust-decay-monitor description: > Helps track how AI skill verification results decay over time. A \"verified\" badge from 18 months ago may be meaningless today — dependencies updated, new attack vectors emerged, the ecosystem changed. Trust has a half-life. version: 1.0.0 metadata: openclaw: requires: bins: [curl, python3] env: [] emoji: \"⏳\" --- That \"Verified\" Badge Is From 2024. Is the Skill Still Safe? ","codeSnippets":[],"executableExamples":[],"parameters":{},"dependencies":[],"permissions":[],"extractedFiles":[],"languages":["typescript"],"docsSourceLabel":"CLAWHUB","editorialOverview":"Helps track how AI skill verification results decay over time. A \"verified\" badge from 18 months ago may be meaningless today — dependencies updated, new attack vectors emerged, the ecosystem changed. Trust has a half-life. --- name: trust-decay-monitor description: > Helps track how AI skill verification results decay over time. A \"verified\" badge from 18 months ago may be meaningless today — dependencies updated, new attack vectors emerged, the ecosystem changed. Trust has a half-life. version: 1.0.0 metadata: openclaw: requires: bins: [curl, python3] env: [] emoji: \"⏳\" --- That \"Verified\" Badge Is From 2024. Is the Skill Still Safe?","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":406,"uniquenessScore":63,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-04-15T00:45:39.800Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-10T06:31:18.569Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}