Security Audit
astica-ai-automation
github.com/ComposioHQ/awesome-claude-skillsTrust Assessment
astica-ai-automation received a trust score of 85/100, placing it in the Mostly Trusted category. This skill has passed most security checks with only minor considerations noted.
SkillShield's automated analysis identified 1 finding: 0 critical, 1 high, 0 medium, and 0 low severity. Key findings include Undefined broad capabilities of RUBE_REMOTE_WORKBENCH.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on February 20, 2026 (commit 27904475). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings1
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| HIGH | Undefined broad capabilities of RUBE_REMOTE_WORKBENCH The skill documentation mentions `RUBE_REMOTE_WORKBENCH` for 'Bulk ops' with `run_composio_tool()`. The term 'Remote Workbench' and the ability to 'run_composio_tool()' suggest this tool might have very broad and potentially unconstrained execution capabilities. Without clear documentation on its scope, sandboxing mechanisms, and what `run_composio_tool()` can execute, there is a significant risk of excessive permissions. If `run_composio_tool()` can execute arbitrary Composio tools, and some of those tools have access to the file system, network, or other sensitive resources, this could lead to data exfiltration, command injection, or other malicious activities. The skill does not provide any examples or limitations for this tool, making its security implications unclear and potentially dangerous. Provide explicit documentation for `RUBE_REMOTE_WORKBENCH` and `run_composio_tool()`, detailing its exact capabilities, scope, sandboxing mechanisms, and any limitations. Ensure it operates with the principle of least privilege. If it allows execution of other tools, clearly list which tools are permitted and their respective permissions. | LLM | SKILL.md:87 |
Scan History
Embed Code
[](https://skillshield.io/report/4502738314fcbcb3)
Powered by SkillShield