Back to skill

Security audit

Airtable Automation

Security checks across malware telemetry and agentic risk

Overview

The skill is coherent Airtable automation, but it exposes delete and schema-changing Airtable actions without clear safety or confirmation guidance.

Install only if you are comfortable giving the Rube MCP connection access to your Airtable workspace. Before using delete, update-table, create-field, or update-field actions, require the agent to show the exact base, table, records, and schema changes and wait for explicit approval; prefer testing on a non-production base first.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill explicitly documents destructive capabilities such as record deletion and schema modification, but it provides no warning, confirmation guidance, or safety constraints before those operations are performed. In an agentic setting, this increases the chance of accidental data loss or breaking Airtable workflows because the skill normalizes high-risk actions alongside routine read/write tasks without requiring explicit user acknowledgment.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.