Security Audit
sympla-automation
github.com/ComposioHQ/awesome-claude-skillsTrust Assessment
sympla-automation received a trust score of 94/100, placing it in the Trusted category. This skill has passed all critical security checks and demonstrates strong security practices.
SkillShield's automated analysis identified 1 finding: 0 critical, 0 high, 1 medium, and 0 low severity. Key findings include Excessive Permissions via RUBE_REMOTE_WORKBENCH.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on February 17, 2026 (commit 99e2a295). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings1
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| MEDIUM | Excessive Permissions via RUBE_REMOTE_WORKBENCH The skill promotes the use of `RUBE_REMOTE_WORKBENCH` for 'Bulk ops' with `run_composio_tool()`. This tool, as described, implies the ability to execute any Composio tool available through Rube MCP, not just Sympla-specific operations. This grants the LLM access to a potentially much broader set of functionalities and data than intended for a 'Sympla Automation' skill, leading to excessive permissions if not properly constrained by the Rube MCP configuration or the LLM's internal policies. An LLM, if not carefully constrained, could use this broad capability to interact with other connected toolkits beyond Sympla. Clarify the scope of `RUBE_REMOTE_WORKBENCH` when used in the context of Sympla automation. If its capabilities extend beyond Sympla, consider advising against its general use for Sympla tasks, or ensure that the Rube MCP configuration strictly limits `run_composio_tool()` to Sympla-related operations for this skill. Alternatively, provide specific examples of how `RUBE_REMOTE_WORKBENCH` can be used *only* for Sympla bulk operations. | LLM | SKILL.md:69 |
Scan History
Embed Code
[](https://skillshield.io/report/8bf9153bdb88298b)
Powered by SkillShield