Security Audit
flutterwave-automation
github.com/ComposioHQ/awesome-claude-skillsTrust Assessment
flutterwave-automation received a trust score of 85/100, placing it in the Mostly Trusted category. This skill has passed most security checks with only minor considerations noted.
SkillShield's automated analysis identified 1 finding: 0 critical, 1 high, 0 medium, and 0 low severity. Key findings include Broad access to financial operations via Rube MCP tools.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on February 20, 2026 (commit 27904475). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings1
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| HIGH | Broad access to financial operations via Rube MCP tools The skill provides access to `RUBE_MULTI_EXECUTE_TOOL` and `RUBE_REMOTE_WORKBENCH`, which allow the execution of arbitrary Flutterwave operations through the connected Rube MCP. While this is the intended functionality of an automation skill, it grants the LLM broad control over financial transactions and sensitive data within Flutterwave. If the LLM is compromised or misused, this broad access could lead to unauthorized financial operations, data manipulation, or other severe consequences. The skill's description does not outline any granular permission controls for specific Flutterwave actions, relying entirely on the permissions of the connected Rube MCP account. Implement more granular access control mechanisms within the Rube MCP Flutterwave toolkit or the LLM's execution environment to restrict the types of Flutterwave operations an LLM can perform based on context or user intent. For sensitive financial operations, consider requiring human-in-the-loop approval or explicit confirmation. | LLM | SKILL.md:46 |
Scan History
Embed Code
[](https://skillshield.io/report/6bbcecdd31ff9b25)
Powered by SkillShield