Security Audit
pdfmonkey-automation
github.com/ComposioHQ/awesome-claude-skillsTrust Assessment
pdfmonkey-automation received a trust score of 96/100, placing it in the Trusted category. This skill has passed all critical security checks and demonstrates strong security practices.
SkillShield's automated analysis identified 1 finding: 0 critical, 0 high, 1 medium, and 0 low severity. Key findings include Broad tool execution via RUBE_REMOTE_WORKBENCH.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on February 17, 2026 (commit 99e2a295). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings1
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| MEDIUM | Broad tool execution via RUBE_REMOTE_WORKBENCH The skill `pdfmonkey-automation` describes the use of `RUBE_REMOTE_WORKBENCH` with `run_composio_tool()` for 'Bulk ops'. While the skill's primary focus is Pdfmonkey, `RUBE_REMOTE_WORKBENCH` with `run_composio_tool()` appears to be a generic tool execution mechanism within the Composio ecosystem. If `run_composio_tool()` can execute tools from other Composio toolkits (e.g., filesystem, network, etc.) and is not strictly scoped to Pdfmonkey tools, this skill could enable an LLM to access capabilities beyond its stated purpose, leading to excessive permissions. The skill's documentation does not explicitly state that `run_composio_tool()` is limited to Pdfmonkey-specific operations. Clarify the scope of `run_composio_tool()` when used with `RUBE_REMOTE_WORKBENCH`. If it's intended only for Pdfmonkey operations, ensure the underlying Rube MCP system enforces this limitation or update the skill's documentation to explicitly state this restriction. If it's intentionally broad, consider if this skill should expose such a powerful, generic execution tool given its specific 'Pdfmonkey Automation' name, or rename the skill to reflect its broader capabilities. | LLM | SKILL.md:64 |
Scan History
Embed Code
[](https://skillshield.io/report/9b34188114188307)
Powered by SkillShield