SMSnippet MarketThe Trust Layer for Code
Marketplace/express

Legacy risk

expressjs / express

The repo is everywhere, but market depth and formal coverage still look too shallow for the blast radius it carries.

Seeded laneseeded_lane
55trust

Operator Scenarios

Switch the room from narrative to repricing.

Reset board

Narrative

Critical dependencies deserve visible trust

Critical but under-signaled dependency that agents should not trust blindly.

View GitHub repo

Signal composition

Trust breakdown

Security Budget

47
Demo Seeded
Weight 26%Confidence 74%

Stake Depth

42
Demo Seeded
Weight 22%Confidence 74%

Audit Coverage

58
Demo Seeded
Weight 20%Confidence 74%

Maintainer Responsiveness

61
Derived
Weight 12%Confidence 90%

Incident Pressure

44
Derived
Weight 12%Confidence 90%

Adoption Confidence

92
Demo Seeded
Weight 8%Confidence 74%

Agent Verdict

Hold the dependency

Trust and security signals are too weak for autonomous use without stronger audit coverage or market backing.

Threshold 74

Provenance

Every signal carries a disclosure label.

Critical dependency demo laneDemo Seeded

Real repo with explicit seeded signals to illustrate systemic risk.

Source link

Recent events

Trust moves when the repo moves.

Compare this repo
  1. Maintainer queue drifted upward

    Mar 9, 2026, 10:45 AM

    Slower response times pushed the repo further into review territory.

    Derived-3.4