Security Audit
plisio-automation
github.com/ComposioHQ/awesome-claude-skillsTrust Assessment
plisio-automation received a trust score of 86/100, placing it in the Mostly Trusted category. This skill has passed most security checks with only minor considerations noted.
SkillShield's automated analysis identified 1 finding: 0 critical, 1 high, 0 medium, and 0 low severity. Key findings include Broad Access to Sensitive Financial Operations.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on February 17, 2026 (commit 99e2a295). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings1
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| HIGH | Broad Access to Sensitive Financial Operations The skill integrates with Plisio, a cryptocurrency payment gateway, via the Rube MCP. It exposes powerful tools like `RUBE_MULTI_EXECUTE_TOOL` and `RUBE_REMOTE_WORKBENCH` which allow the LLM to execute arbitrary Plisio operations. This grants the LLM broad access to sensitive financial functionalities, including potentially creating invoices, managing payments, and querying financial data. While the skill's purpose is automation, an LLM could be prompted to misuse these capabilities, leading to unauthorized financial transactions or data exposure. The skill documentation does not specify granular permission controls, relying on the underlying Rube MCP and Plisio toolkit to manage the scope of access. Implement granular access controls within the Plisio toolkit (if possible) to limit the scope of operations an LLM can perform. Require explicit human confirmation for high-impact financial operations (e.g., initiating payments). Ensure the Rube MCP and Plisio toolkit enforce strong authentication and authorization. Provide clearer guidance in the skill documentation on the specific Plisio operations exposed and their potential impact. | LLM | SKILL.md:50 |
Scan History
Embed Code
[](https://skillshield.io/report/8a10e2c132a9fc21)
Powered by SkillShield