Security Audit
ascora-automation
github.com/ComposioHQ/awesome-claude-skillsTrust Assessment
ascora-automation received a trust score of 100/100, placing it in the Trusted category. This skill has passed all critical security checks and demonstrates strong security practices.
SkillShield's automated analysis identified 1 finding: 0 critical, 0 high, 0 medium, and 0 low severity. Key findings include Broad Tool Execution Capability via Rube MCP.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on February 17, 2026 (commit 99e2a295). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings1
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| INFO | Broad Tool Execution Capability via Rube MCP The skill's manifest requires access to the Rube Managed Capability Provider (MCP). The documentation describes tools like `RUBE_MULTI_EXECUTE_TOOL` and `RUBE_REMOTE_WORKBENCH` (with `run_composio_tool()`) which allow the agent to execute any Composio tool available through the Rube MCP. This grants the agent a broad range of capabilities, potentially extending beyond just Ascora operations to any service integrated with Composio via Rube. While this is the intended design of an MCP-based skill, users should be aware of the wide scope of actions an agent can perform when this skill is enabled, as a compromised or misdirected agent could leverage these capabilities for unintended operations across various integrated services. Review the specific Composio tools exposed by Rube MCP to understand the full scope of actions an agent can perform. Implement strict access controls or agent policies to limit the use of broad tools like `RUBE_MULTI_EXECUTE_TOOL` and `RUBE_REMOTE_WORKBENCH` to only necessary operations for the intended use case. | LLM | SKILL.md:50 |
Scan History
Embed Code
[](https://skillshield.io/report/b75666623abe87e2)
Powered by SkillShield