Bamboohr Automation
v0.1.0Automate BambooHR tasks via Rube MCP (Composio): employees, time-off, benefits, dependents, employee updates. Always search tools first for current schemas.
⭐ 1· 1.5k·3 current·3 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Suspicious
medium confidencePurpose & Capability
The name/description (BambooHR automation) matches the SKILL.md workflows and referenced toolkit calls (employee listing, time-off, dependents, updates). There are no unrelated binaries or environment variables requested.
Instruction Scope
Instructions tell the agent to use Rube MCP tool calls (RUBE_SEARCH_TOOLS, RUBE_MANAGE_CONNECTIONS, BAMBOOHR_* operations) which are within scope, but they also instruct the user to add an external MCP endpoint (https://rube.app/mcp) and state "No API keys needed — just add the endpoint and it works." That is vague about where authentication happens and whether BambooHR credentials or tokens will be sent to / stored by a third party, creating a potential data-exfiltration/privacy risk.
Install Mechanism
This is an instruction-only skill with no install spec and no code files — lowest install risk. Nothing is written to disk by the skill itself.
Credentials
The skill declares no required environment variables or credentials, but it depends on a third-party MCP (rube) to manage BambooHR connections. That design offloads credential handling to the MCP server; the SKILL.md does not specify who hosts the MCP, how tokens are stored, or what access the MCP operator will have to sensitive HR data, which is disproportionate given the sensitive nature of employee records.
Persistence & Privilege
Skill does not request always: true, no install steps, and does not ask to modify other skills or system-wide settings. Autonomous invocation is allowed (platform default) but not combined with other high privileges.
What to consider before installing
This skill appears to be a thin instruction wrapper around a Rube MCP-managed BambooHR toolkit. Before installing or using it: (1) Confirm who operates the MCP endpoint (https://rube.app/mcp) and whether you trust that operator to handle HR data and credentials. (2) Ask where BambooHR auth tokens are stored and whether the MCP can access or export employee data. (3) Prefer using an MCP you control or an officially supported integration that documents OAuth/API key handling. (4) Limit permissions for the BambooHR connection to the minimum required and test on non-production data first. If you cannot verify the MCP's trustworthiness and data handling, avoid using the skill.Like a lobster shell, security has layers — review code before you run it.
latestvk978m3nmdqrh8zhb0sv0ay6gfh80nvna
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
