Security Audit
cloudflare-browser-rendering-automation
github.com/ComposioHQ/awesome-claude-skillsTrust Assessment
cloudflare-browser-rendering-automation received a trust score of 85/100, placing it in the Mostly Trusted category. This skill has passed most security checks with only minor considerations noted.
SkillShield's automated analysis identified 1 finding: 0 critical, 1 high, 0 medium, and 0 low severity. Key findings include Generic tool execution via RUBE_REMOTE_WORKBENCH.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on February 20, 2026 (commit 27904475). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings1
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| HIGH | Generic tool execution via RUBE_REMOTE_WORKBENCH The skill documentation suggests using `RUBE_REMOTE_WORKBENCH` with `run_composio_tool()` for 'Bulk ops'. This implies the ability to execute arbitrary Composio tools available through the Rube MCP, not just those specifically related to Cloudflare Browser Rendering. If the Rube MCP has access to other toolkits (e.g., filesystem, network, or other sensitive APIs), this could allow the skill to perform actions outside its stated purpose, leading to excessive permissions and potential privilege escalation beyond the 'cloudflare-browser-rendering-automation' scope. Clarify or restrict the scope of `RUBE_REMOTE_WORKBENCH` when used within this skill to only allow Cloudflare Browser Rendering-related tools. If `run_composio_tool()` is inherently generic, consider if this skill truly needs access to such a broad capability, or if a more specific tool execution method should be used that adheres to the principle of least privilege for this skill's stated purpose. | LLM | SKILL.md:88 |
Scan History
Embed Code
[](https://skillshield.io/report/44f031888c60bf21)
Powered by SkillShield