Security Audit
docusign-automation
github.com/ComposioHQ/awesome-claude-skillsTrust Assessment
docusign-automation received a trust score of 95/100, placing it in the Trusted category. This skill has passed all critical security checks and demonstrates strong security practices.
SkillShield's automated analysis identified 1 finding: 0 critical, 0 high, 1 medium, and 0 low severity. Key findings include Broad DocuSign API Access.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on February 17, 2026 (commit 99e2a295). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings1
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| MEDIUM | Broad DocuSign API Access The skill provides access to a comprehensive set of DocuSign API functionalities, including listing, creating, sending, and managing envelopes and templates. This broad access means that a compromised agent could perform a wide range of sensitive actions within the connected DocuSign account, such as sending unauthorized documents for signature, voiding existing envelopes, or accessing confidential template details. While these permissions are necessary for the skill's intended automation, they represent a significant attack surface if the agent's control flow is compromised. Ensure strict control over agent prompts and inputs to prevent unauthorized use of DocuSign functionalities. Users should be fully aware of the extensive capabilities granted to the agent through this skill. If possible, consider implementing more granular permissions within the DocuSign integration (e.g., via Rube MCP configuration) if specific use cases require limited access to only a subset of DocuSign operations. | LLM | SKILL.md:26 |
Scan History
Embed Code
[](https://skillshield.io/report/a368189064530913)
Powered by SkillShield