Security Audit
rootly-automation
github.com/ComposioHQ/awesome-claude-skillsTrust Assessment
rootly-automation received a trust score of 95/100, placing it in the Trusted category. This skill has passed all critical security checks and demonstrates strong security practices.
SkillShield's automated analysis identified 1 finding: 0 critical, 0 high, 1 medium, and 0 low severity. Key findings include Broad access to Rootly operations via Rube MCP.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on February 17, 2026 (commit 99e2a295). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings1
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| MEDIUM | Broad access to Rootly operations via Rube MCP The skill's primary purpose is to 'Automate Rootly operations' through the Rube MCP. This inherently grants the agent broad access to perform any action allowed by the connected Rootly account (e.g., creating/deleting incidents, managing users, accessing sensitive incident data). While the skill advises dynamic tool discovery and schema compliance, it does not implement or suggest any internal mechanisms for fine-grained access control or scope limitation on the Rootly operations that can be performed. If the agent is compromised, an attacker could leverage this broad access to perform unauthorized and potentially destructive actions within Rootly. Implement granular access control policies for the Rootly connection within the Rube MCP, ensuring the connected account has only the minimum necessary permissions. The agent using this skill should also be configured with internal policies to restrict the scope of Rootly operations it is allowed to perform, even if the underlying connection has broader permissions. | LLM | SKILL.md:3 |
Scan History
Embed Code
[](https://skillshield.io/report/5b89873bcbb3e688)
Powered by SkillShield