Security Audit
share_point-automation
github.com/ComposioHQ/awesome-claude-skillsTrust Assessment
share_point-automation received a trust score of 85/100, placing it in the Mostly Trusted category. This skill has passed most security checks with only minor considerations noted.
SkillShield's automated analysis identified 1 finding: 0 critical, 0 high, 1 medium, and 0 low severity. Key findings include Skill promotes use of arbitrary code execution tool.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on February 20, 2026 (commit 27904475). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings1
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| MEDIUM | Skill promotes use of arbitrary code execution tool The skill instructs the LLM to use `RUBE_REMOTE_WORKBENCH` for 'bulk operations' and 'data processing'. This tool allows the execution of arbitrary Python code within a sandboxed environment. While intended for legitimate purposes, this capability grants broad execution permissions. If the LLM is compromised or instructed maliciously, it could generate and execute arbitrary code via this workbench, potentially leading to data exfiltration, unauthorized actions, or resource abuse within the sandbox's allowed scope. Clarify the scope and security implications of `RUBE_REMOTE_WORKBENCH` usage. Provide stricter guidelines or examples for its use, emphasizing that only trusted and validated code should be executed. Consider if such a powerful tool should be directly exposed or if more constrained alternatives exist for common bulk operations. | LLM | SKILL.md:60 |
Scan History
Embed Code
[](https://skillshield.io/report/2877996458e3cd7f)
Powered by SkillShield