Security Audit
smartrecruiters-automation
github.com/ComposioHQ/awesome-claude-skillsTrust Assessment
smartrecruiters-automation received a trust score of 85/100, placing it in the Mostly Trusted category. This skill has passed most security checks with only minor considerations noted.
SkillShield's automated analysis identified 1 finding: 0 critical, 0 high, 1 medium, and 0 low severity. Key findings include Exposure of Broad Automation Capabilities via RUBE_REMOTE_WORKBENCH.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on February 20, 2026 (commit 27904475). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings1
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| MEDIUM | Exposure of Broad Automation Capabilities via RUBE_REMOTE_WORKBENCH The skill documentation exposes the `RUBE_REMOTE_WORKBENCH` tool, specifically mentioning its use for "Bulk ops" with `run_composio_tool()`. This indicates that the LLM, when using this skill, has access to a highly privileged interface capable of performing complex and potentially large-scale operations on Smartrecruiters. While the skill itself doesn't define the exact scope of `run_composio_tool()`, its "bulk ops" nature suggests a significant potential for unauthorized data manipulation, exfiltration, or service disruption if the LLM's execution context is compromised. Implement granular access controls and strict validation within the Rube MCP system for `RUBE_REMOTE_WORKBENCH` and `run_composio_tool()`. Ensure that any "bulk operations" require explicit user confirmation or are limited to predefined, safe workflows. The skill documentation should also clarify the precise scope and potential impact of this tool. | LLM | SKILL.md:60 |
Scan History
Embed Code
[](https://skillshield.io/report/a281cb8277e057a1)
Powered by SkillShield