Security Audit
salesforce-service-cloud-automation
github.com/ComposioHQ/awesome-claude-skillsTrust Assessment
salesforce-service-cloud-automation received a trust score of 88/100, placing it in the Mostly Trusted category. This skill has passed most security checks with only minor considerations noted.
SkillShield's automated analysis identified 1 finding: 0 critical, 1 high, 0 medium, and 0 low severity. Key findings include Vague description of powerful 'RUBE_REMOTE_WORKBENCH' tool.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on February 17, 2026 (commit 99e2a295). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings1
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| HIGH | Vague description of powerful 'RUBE_REMOTE_WORKBENCH' tool The skill documentation mentions 'RUBE_REMOTE_WORKBENCH' with 'run_composio_tool()' for 'Bulk ops' but provides no details on its capabilities, security boundaries, or input validation. A 'remote workbench' often implies a powerful execution environment, and 'run_composio_tool()' suggests arbitrary execution of Composio tools. This lack of transparency for a potentially highly privileged operation poses a significant risk. An LLM might be prompted to use this tool for unintended or malicious purposes, potentially leading to excessive permissions, data manipulation, or even command injection if the workbench allows arbitrary code execution or broad system access without proper sandboxing or explicit user consent. Provide a detailed explanation of `RUBE_REMOTE_WORKBENCH`'s capabilities, security boundaries, and input validation. Clearly specify what 'run_composio_tool()' entails, what kind of 'bulk ops' are supported, and any limitations or safeguards. If it allows arbitrary code execution or broad system access, this should be explicitly stated along with necessary security controls and user consent mechanisms. | LLM | SKILL.md:70 |
Scan History
Embed Code
[](https://skillshield.io/report/c373faf6e758a768)
Powered by SkillShield