94OUT OF 100
TrustedHigh trustStatic read

wolfi-dev/wolfictl

wolfictl is a well-documented Go CLI tool for the Wolfi project. The repository shows no signs of malicious behavior, obfuscation, or unauthorized network activity in our static analysis. The installation process is standard for Go projects and aligns with the declared intent in the README.

Repository size
11489 KB
Packages
0
Stars
72
Created
3 yr 11 mo
Reputation signals
wolfi-dev avatar
Wolfi
@wolfi-dev
Account age3 yr 11 mo
Public repos16
Forks85
Community sentiment85

Positive

Code & behavior signals
No risky items found

No signatures, install hooks, obfuscation, or embedded secrets were found in the code.

Per-package scoring
Final verdict

No malicious behavior in our static read, and reputation is strong. Runtime was not executed in a sandbox on this pass, so this is a static-read clearance, not a guarantee.

What we could not verify
—Full runtime behavior (this repo was not executed in a sandbox on this pass)
—Every conditional and time-triggered branch
—Behavior under real credentials (no sandbox was run on this pass)
End-to-end logs
Clone
›Repository cloned successfully from wolfi-dev/wolfictl.
Static scan
›No suspicious patterns, obfuscation, or credential access detected.
Reputation
›Organization is established with consistent activity.
Read
›README intent is consistent with standard Go CLI development practices.
Score
›Score computed by formula: 94/100 (deterministic, code-driven)
›+8 [reputation] established_owner: Owner account is established (older than a year with multiple public repos).
›+4 [reputation] good_sentiment: Positive community sentiment (85/100).
Auto-published at clauderabbit.in/wolfi-dev/wolfictl · re-checked when the repo changes