Security Audit
astica-ai-automation
github.com/ComposioHQ/awesome-claude-skillsTrust Assessment
astica-ai-automation received a trust score of 95/100, placing it in the Trusted category. This skill has passed all critical security checks and demonstrates strong security practices.
SkillShield's automated analysis identified 1 finding: 0 critical, 0 high, 1 medium, and 0 low severity. Key findings include Potential for excessive permissions via RUBE_REMOTE_WORKBENCH.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on February 17, 2026 (commit 99e2a295). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings1
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| MEDIUM | Potential for excessive permissions via RUBE_REMOTE_WORKBENCH The skill documentation mentions `RUBE_REMOTE_WORKBENCH` for 'Bulk ops' with `run_composio_tool()`. The term 'remote workbench' often implies an environment capable of executing arbitrary code or scripts. Without clear documentation on the sandboxing and limitations of this workbench and the `run_composio_tool()` function, there is a risk that an agent could be instructed to execute commands or access resources beyond the intended scope, potentially leading to excessive permissions or command injection on the remote system. Provide explicit documentation on the security model, sandboxing, and capabilities of `RUBE_REMOTE_WORKBENCH` and `run_composio_tool()`. Clearly define what types of operations are permitted and what resources are accessible within the workbench environment. If it allows arbitrary code execution, consider if this level of access is truly necessary for the skill's intended purpose and implement stricter controls. | LLM | SKILL.md:84 |
Scan History
Embed Code
[](https://skillshield.io/report/3ba60b902648302d)
Powered by SkillShield