Security Audit
diffbot-automation
github.com/ComposioHQ/awesome-claude-skillsTrust Assessment
diffbot-automation received a trust score of 95/100, placing it in the Trusted category. This skill has passed all critical security checks and demonstrates strong security practices.
SkillShield's automated analysis identified 1 finding: 0 critical, 0 high, 1 medium, and 0 low severity. Key findings include Broad access via RUBE_REMOTE_WORKBENCH.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on February 17, 2026 (commit 99e2a295). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings1
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| MEDIUM | Broad access via RUBE_REMOTE_WORKBENCH The skill's manifest requires access to the entire 'rube' MCP. The documentation for this skill mentions the 'RUBE_REMOTE_WORKBENCH' tool for 'Bulk ops' using 'run_composio_tool()'. If 'run_composio_tool()' allows execution of arbitrary Composio tools or arbitrary code within the Composio ecosystem without specific restrictions to Diffbot operations, this represents an overly broad permission scope. An AI agent, if compromised or misdirected, could potentially leverage this tool to perform actions beyond the intended 'Diffbot automation', leading to unintended consequences or unauthorized access to other Composio functionalities. If possible, restrict the 'rube' MCP requirement in the manifest to only the specific Diffbot-related tools necessary for this skill. Clarify the exact scope and capabilities of 'run_composio_tool()' within 'RUBE_REMOTE_WORKBENCH' to ensure it is appropriately sandboxed and limited to Diffbot operations. If 'run_composio_tool()' can execute arbitrary code or a wide range of Composio tools, this should be explicitly stated, justified, and potentially re-evaluated for security implications. | LLM | SKILL.md:68 |
Scan History
Embed Code
[](https://skillshield.io/report/2917e6c92fecc886)
Powered by SkillShield