Security Audit
updown-io-automation
github.com/ComposioHQ/awesome-claude-skillsTrust Assessment
updown-io-automation received a trust score of 95/100, placing it in the Trusted category. This skill has passed all critical security checks and demonstrates strong security practices.
SkillShield's automated analysis identified 1 finding: 0 critical, 0 high, 1 medium, and 0 low severity. Key findings include Potential for excessive tool access via RUBE_REMOTE_WORKBENCH.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on February 17, 2026 (commit 99e2a295). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings1
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| MEDIUM | Potential for excessive tool access via RUBE_REMOTE_WORKBENCH The skill documentation mentions `RUBE_REMOTE_WORKBENCH` for 'Bulk ops' using `run_composio_tool()`. This tool appears to be a generic mechanism for executing arbitrary Composio tools. If the Composio platform includes toolkits with broad system access (e.g., filesystem, network requests to arbitrary domains, shell execution) and these can be invoked via `run_composio_tool()`, then this skill, by instructing the agent to use `RUBE_REMOTE_WORKBENCH`, could grant the agent excessive permissions beyond its stated purpose of 'Updown IO Automation'. The scope of `run_composio_tool()` is not clearly defined as being limited to Updown IO specific operations. Clarify the scope of `RUBE_REMOTE_WORKBENCH` and `run_composio_tool()`. If it's intended to be limited to the current toolkit's operations, this should be explicitly stated. If it can access other toolkits, consider if this broad access is necessary for an 'Updown IO Automation' skill and if the underlying Composio platform enforces proper sandboxing and access controls for different toolkits. | LLM | SKILL.md:80 |
Scan History
Embed Code
[](https://skillshield.io/report/ff4cc62fd1b67296)
Powered by SkillShield