Trust Assessment
cats-automation received a trust score of 95/100, placing it in the Trusted category. This skill has passed all critical security checks and demonstrates strong security practices.
SkillShield's automated analysis identified 1 finding: 0 critical, 0 high, 1 medium, and 0 low severity. Key findings include Broad tool execution capability via Rube MCP.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on February 17, 2026 (commit 99e2a295). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings1
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| MEDIUM | Broad tool execution capability via Rube MCP The skill is named 'cats-automation' and its description focuses on 'Automate Cats tasks'. However, the documentation explicitly highlights the use of `RUBE_REMOTE_WORKBENCH` with `run_composio_tool()`. This function typically allows for the execution of any Composio tool available through the Rube MCP, not just those related to Cats. This broad capability, if not strictly necessary for Cats automation, represents an excessive permission. An agent using this skill could potentially be prompted to execute arbitrary Composio tools, leading to actions outside the intended scope of 'Cats automation'. If the skill is intended solely for 'Cats automation', consider if `RUBE_REMOTE_WORKBENCH` with `run_composio_tool()` is truly necessary. If not, remove this reference or clarify its scope to be Cats-specific. Alternatively, ensure that the Rube MCP configuration restricts the available tools for this skill to only those relevant to Cats. If the broad access is intentional, the skill's name and description should be updated to accurately reflect this wider capability. | LLM | SKILL.md:70 |
Scan History
Embed Code
[](https://skillshield.io/report/e353a2e41636658c)
Powered by SkillShield