Security Audit
postgrid-verify-automation
github.com/ComposioHQ/awesome-claude-skillsTrust Assessment
postgrid-verify-automation received a trust score of 96/100, placing it in the Trusted category. This skill has passed all critical security checks and demonstrates strong security practices.
SkillShield's automated analysis identified 1 finding: 0 critical, 0 high, 1 medium, and 0 low severity. Key findings include Potential for Excessive Permissions via RUBE_REMOTE_WORKBENCH.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on February 17, 2026 (commit 99e2a295). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings1
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| MEDIUM | Potential for Excessive Permissions via RUBE_REMOTE_WORKBENCH The skill's 'Quick Reference' section lists `RUBE_REMOTE_WORKBENCH` with `run_composio_tool()` for 'Bulk ops'. While the overall context of this skill is 'Postgrid Verify Automation', the `RUBE_REMOTE_WORKBENCH` tool's name and its general description ('Bulk ops') suggest it might offer broader capabilities than strictly Postgrid Verify operations. If `run_composio_tool()` within `RUBE_REMOTE_WORKBENCH` can execute arbitrary Composio tools from other toolkits (e.g., filesystem access, network requests, or other sensitive APIs) and is not strictly scoped by the Rube MCP platform to only the `postgrid_verify` toolkit, it could lead to excessive permissions. An LLM, either through a malicious prompt or an unintended interpretation, might leverage this tool to perform actions outside the intended scope of this skill, potentially leading to privilege escalation or unauthorized access to other system functionalities. The Rube MCP platform should ensure that `RUBE_REMOTE_WORKBENCH`, when invoked within the context of a specific skill like 'postgrid-verify-automation', is strictly sandboxed and limited in scope to only the operations and toolkits explicitly intended for that skill. This prevents the LLM from using this powerful tool to access unintended resources or functionalities. Skill developers should also clarify the exact scope and limitations of `RUBE_REMOTE_WORKBENCH` if it's intended to be restricted. | LLM | SKILL.md:72 |
Scan History
Embed Code
[](https://skillshield.io/report/051be6bf632200e9)
Powered by SkillShield