Security Audit
eodhd-apis-automation
github.com/ComposioHQ/awesome-claude-skillsTrust Assessment
eodhd-apis-automation received a trust score of 85/100, placing it in the Mostly Trusted category. This skill has passed most security checks with only minor considerations noted.
SkillShield's automated analysis identified 1 finding: 0 critical, 1 high, 0 medium, and 0 low severity. Key findings include Broad access to external financial APIs via Rube MCP.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on February 17, 2026 (commit 99e2a295). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings1
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| HIGH | Broad access to external financial APIs via Rube MCP The skill enables an AI agent to discover and execute any available Eodhd API tool via Rube MCP. This grants broad, unrestricted access to financial data and operations provided by Eodhd APIs. If the agent is compromised or misinterprets user intent, it could lead to unauthorized access, manipulation, or exfiltration of sensitive financial information. The skill itself does not define any granular permissions or restrictions on which specific Eodhd API operations can be performed, relying solely on the agent's interpretation and the external Rube/Composio system. Implement granular access controls or a whitelist of allowed Eodhd API operations within the agent's logic or the skill's configuration. Ensure user consent and explicit confirmation are required for sensitive financial operations. Consider using a more restricted Rube MCP toolkit if only a subset of Eodhd API functionality is truly needed, or ensure the agent's internal guardrails are robust enough to prevent misuse of these broad permissions. | Static | SKILL.md:56 |
Scan History
Embed Code
[](https://skillshield.io/report/494bdc359ce4a638)
Powered by SkillShield