How AgentHubStack evaluates tools
AgentHubStack combines public repository signals with editorial review to make tools easier to compare. A trust score is a screening aid, not a security audit, certification, endorsement, or guarantee.
Sources we use
Reviews are based on information visible on public project pages and repositories at the time of review. This can include repository activity, stars, open issues, detected license information, documentation, setup instructions, and publicly stated compatibility.
- Public metadata can be incomplete, delayed, or changed by a maintainer after our review.
- We do not claim access to private repositories, private issue trackers, internal security reports, or unpublished roadmaps.
- Claims from a project are treated as project claims unless independently verifiable from public evidence.
What the trust score measures
The displayed score is a 0–100 comparative signal. The current breakdown considers recent activity, community interest, maintenance load, detected licensing, recorded security or risk notes, and setup difficulty. It may blend those computed signals with a stored editorial score.
The score is designed for triage inside this directory. It is not a probability of safety or quality, and scores from other services are not directly comparable.
Known limitations
- Popularity does not prove security, reliability, or responsible maintenance.
- A recent commit may be minor; an older repository may still be stable and appropriate.
- Issue counts do not show issue severity, response quality, or work completed outside GitHub.
- A detected license does not establish that every dependency, asset, or use case is legally permitted.
- Setup difficulty is a usability signal, not a security finding.
- Security notes are not a substitute for code review, dependency scanning, threat modeling, or testing in your environment.
Checks to make before adoption
Before using a tool with source code, credentials, production data, or write access, inspect its permissions and data flow yourself. Review the current repository, release notes, dependencies, license, open security reports, installation scripts, network access, and rollback path.
Updates and corrections
Listings and scores are snapshots and may become stale. The AgentHubStack Editorial Team may revise a page when public evidence changes or a factual error is identified. To flag an issue tied to a public repository, use the submission route and describe the correction in the note field.