Security Audit
addresszen-automation
github.com/ComposioHQ/awesome-claude-skillsTrust Assessment
addresszen-automation received a trust score of 85/100, placing it in the Mostly Trusted category. This skill has passed most security checks with only minor considerations noted.
SkillShield's automated analysis identified 1 finding: 0 critical, 0 high, 1 medium, and 0 low severity. Key findings include Potential Excessive Permissions via RUBE_REMOTE_WORKBENCH.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on February 20, 2026 (commit 27904475). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings1
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| MEDIUM | Potential Excessive Permissions via RUBE_REMOTE_WORKBENCH The skill recommends using `RUBE_REMOTE_WORKBENCH` for 'Bulk ops' with `run_composio_tool()`. The name 'Workbench' and the ability to run other tools suggest this might be a highly privileged tool. If `RUBE_REMOTE_WORKBENCH` allows arbitrary execution of Composio tools or provides a broader execution environment, it could lead to excessive permissions, allowing an agent to perform actions beyond the intended scope of Addresszen automation. This could potentially include command injection if `run_composio_tool()` can be manipulated to execute arbitrary commands. The skill does not provide sufficient context on the limitations or security implications of this powerful tool. Clarify the exact capabilities and security boundaries of `RUBE_REMOTE_WORKBENCH`. If it provides broad access, consider if its use should be restricted or if more granular tools are available. Provide explicit warnings about its power and potential misuse, and detail any safeguards in place to prevent unauthorized actions. | LLM | SKILL.md:60 |
Scan History
Embed Code
[](https://skillshield.io/report/46d726f0e51f6b92)
Powered by SkillShield