Security Audit
active-campaign-automation
github.com/ComposioHQ/awesome-claude-skillsTrust Assessment
active-campaign-automation received a trust score of 95/100, placing it in the Trusted category. This skill has passed all critical security checks and demonstrates strong security practices.
SkillShield's automated analysis identified 1 finding: 0 critical, 0 high, 1 medium, and 0 low severity. Key findings include Skill documents broad tool access beyond its stated scope.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on February 17, 2026 (commit 99e2a295). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings1
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| MEDIUM | Skill documents broad tool access beyond its stated scope The skill 'active-campaign-automation' is explicitly designed for ActiveCampaign tasks, as indicated by its name and description. However, its documentation includes `RUBE_REMOTE_WORKBENCH` with `run_composio_tool()` as an approach for 'Bulk ops'. If `run_composio_tool()` is a generic function capable of invoking tools from *any* Composio toolkit (e.g., Slack, GitHub, etc.), then this skill's documentation implicitly suggests a capability for broader tool access than its stated purpose. An LLM might interpret this as permission to use `run_composio_tool()` for non-ActiveCampaign tasks, potentially leading to excessive permissions being exercised by a skill with a narrow stated scope. Clarify the scope of `run_composio_tool()` within this skill's context. If it is intended only for ActiveCampaign tools, state that explicitly in the documentation. If it can indeed access other toolkits, consider if this skill's scope should be broadened, or if this specific entry should be removed/modified to align strictly with 'ActiveCampaign automation'. | LLM | SKILL.md:70 |
Scan History
Embed Code
[](https://skillshield.io/report/3d59f799d317f8f3)
Powered by SkillShield