Security Audit
prerender-automation
github.com/ComposioHQ/awesome-claude-skillsTrust Assessment
prerender-automation received a trust score of 93/100, placing it in the Trusted category. This skill has passed all critical security checks and demonstrates strong security practices.
SkillShield's automated analysis identified 1 finding: 0 critical, 0 high, 1 medium, and 0 low severity. Key findings include Potential for broad tool execution via RUBE_REMOTE_WORKBENCH.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on February 17, 2026 (commit 99e2a295). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings1
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| MEDIUM | Potential for broad tool execution via RUBE_REMOTE_WORKBENCH The skill documentation mentions `RUBE_REMOTE_WORKBENCH` with `run_composio_tool()` for 'Bulk ops'. While the skill's stated purpose is 'Prerender automation' and other tool calls are explicitly scoped to 'Prerender operations', the function name `run_composio_tool()` is generic. This could imply the ability to execute any tool available through Composio, not just those specific to the Prerender toolkit. If this function is not strictly scoped to Prerender operations, it could grant the LLM overly broad access to other functionalities, leading to unintended actions or data access beyond the skill's intended scope. Clarify the scope of `run_composio_tool()` when used within this skill. If it is intended to be restricted to Prerender operations, ensure this is explicitly stated in the documentation or enforced by the underlying Rube MCP. If it is truly generic, consider if this skill requires such broad access or if a more narrowly scoped alternative is available. | Static | SKILL.md:70 |
Scan History
Embed Code
[](https://skillshield.io/report/852e6e7cfb5f84c4)
Powered by SkillShield