Security Audit
bitwarden-automation
github.com/ComposioHQ/awesome-claude-skillsTrust Assessment
bitwarden-automation received a trust score of 86/100, placing it in the Mostly Trusted category. This skill has passed most security checks with only minor considerations noted.
SkillShield's automated analysis identified 1 finding: 0 critical, 1 high, 0 medium, and 0 low severity. Key findings include Broad Access to Sensitive Password Manager.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on February 17, 2026 (commit 99e2a295). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings1
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| HIGH | Broad Access to Sensitive Password Manager The 'bitwarden-automation' skill, by its nature, grants an LLM agent broad access to a user's Bitwarden vault via the Rube MCP. This includes the ability to perform various Bitwarden operations (e.g., retrieve, create, update, delete entries) as indicated by the 'Core Workflow Pattern' and 'Quick Reference' sections. While this is the intended functionality of an automation skill for Bitwarden, it represents a significant security risk if the agent or the underlying Rube MCP system is compromised. A compromised agent could potentially access and exfiltrate highly sensitive credential data, leading to severe security breaches. Implement robust access controls and monitoring for the LLM agent's interactions with this skill. Ensure the Rube MCP and its Bitwarden toolkit are securely configured and regularly audited. Users should be fully aware of the extensive permissions granted to the agent when enabling this skill and only use it in highly trusted environments. If possible, configure the Bitwarden connection with the principle of least privilege, limiting the scope of operations or specific vault items the agent can access. | LLM | SKILL.md:1 |
Scan History
Embed Code
[](https://skillshield.io/report/5443c66b4b2a03b6)
Powered by SkillShield