Security Audit
hackernews-automation
github.com/ComposioHQ/awesome-claude-skillsTrust Assessment
hackernews-automation received a trust score of 100/100, placing it in the Trusted category. This skill has passed all critical security checks and demonstrates strong security practices.
SkillShield's automated analysis identified 1 finding: 0 critical, 0 high, 0 medium, and 0 low severity. Key findings include Reliance on external MCP system introduces supply chain risk.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on February 17, 2026 (commit 99e2a295). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings1
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| INFO | Reliance on external MCP system introduces supply chain risk The skill explicitly requires and relies on the 'rube' Managed Control Plane (MCP) system, as indicated in the manifest (`requires: {"mcp": ["rube"]}`) and throughout the `SKILL.md` documentation. This system is hosted externally at `rube.app` and `composio.dev`. While this is the intended functionality, it introduces a supply chain risk. The security of this skill is dependent on the security posture of the Rube MCP infrastructure and the Composio platform. Compromise of these external services or vulnerabilities within their tools could impact the security and integrity of operations performed by this skill. Acknowledge and monitor the security posture of external dependencies like Rube MCP and Composio. Ensure that the MCP provider has robust security practices and incident response. Consider implementing additional checks or sandboxing for operations performed via external MCPs, especially when handling sensitive data or critical actions. | Static | SKILL.md:1 |
Scan History
Embed Code
[](https://skillshield.io/report/62da270d5335d04b)
Powered by SkillShield