Security Audit
eversign-automation
github.com/ComposioHQ/awesome-claude-skillsTrust Assessment
eversign-automation received a trust score of 85/100, placing it in the Mostly Trusted category. This skill has passed most security checks with only minor considerations noted.
SkillShield's automated analysis identified 1 finding: 0 critical, 1 high, 0 medium, and 0 low severity. Key findings include Potential Command Injection via RUBE_REMOTE_WORKBENCH.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on February 20, 2026 (commit 27904475). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings1
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| HIGH | Potential Command Injection via RUBE_REMOTE_WORKBENCH The skill's 'Quick Reference' section recommends using `RUBE_REMOTE_WORKBENCH` with `run_composio_tool()` for 'Bulk ops'. The term 'workbench' and 'run_composio_tool()' strongly suggest capabilities for executing code or commands. If the inputs to `RUBE_REMOTE_WORKBENCH` or `run_composio_tool()` are not rigorously validated and sanitized, this could allow a malicious actor to inject and execute arbitrary commands, leading to command injection and potentially excessive permissions on the underlying system. The skill description provides no warnings or guidance on how to securely use this powerful tool. Add explicit warnings and detailed guidance on the secure use of `RUBE_REMOTE_WORKBENCH` and `run_composio_tool()`. Clearly document its capabilities, potential risks, and any required input validation or sandboxing mechanisms. If arbitrary code execution is possible, this should be highlighted, and strong security controls must be in place and communicated. | LLM | SKILL.md:80 |
Scan History
Embed Code
[](https://skillshield.io/report/3ca8dc388fc8751f)
Powered by SkillShield