Security Audit
ip2location-io-automation
github.com/ComposioHQ/awesome-claude-skillsTrust Assessment
ip2location-io-automation received a trust score of 94/100, placing it in the Trusted category. This skill has passed all critical security checks and demonstrates strong security practices.
SkillShield's automated analysis identified 1 finding: 0 critical, 0 high, 1 medium, and 0 low severity. Key findings include Excessive Permissions via General Tool Execution.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on February 17, 2026 (commit 99e2a295). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings1
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| MEDIUM | Excessive Permissions via General Tool Execution The skill's primary purpose is 'Ip2location IO Automation' as stated in the manifest and skill description. However, the 'Quick Reference' section explicitly mentions and provides guidance for using `RUBE_REMOTE_WORKBENCH` with `run_composio_tool()`. The `run_composio_tool()` function implies the ability to execute any Composio tool available through the Rube MCP, not just those specific to Ip2location IO. This grants the LLM access to a broader set of capabilities than the skill's stated scope, potentially allowing it to interact with other toolkits or perform operations unintended for this specific skill. If the skill's intended scope is strictly Ip2location IO, remove the mention of `RUBE_REMOTE_WORKBENCH` with `run_composio_tool()` or ensure that its functionality is strictly limited to Ip2location IO operations. If the skill is intended to be a general Composio tool orchestrator, update the skill's description and name to accurately reflect this broader scope. | LLM | SKILL.md:67 |
Scan History
Embed Code
[](https://skillshield.io/report/c6a21face2048b21)
Powered by SkillShield