Composio CLI

Warn

Audited by Socket on May 16, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: the skill's broad SaaS-action purpose matches its capabilities, and the installer appears to be the publisher's official path, so this is not clearly malicious. However, it carries meaningful security risk from same-org `curl|bash` installation, centralized credential forwarding through Composio's backend, and default transitive skill installation during login.

Confidence: 87%Severity: 56%
Audit Metadata
Analyzed At
May 16, 2026, 05:41 AM
Package URL
pkg:socket/skills-sh/ComposioHQ%2Fawesome-agent-clis%2Fcomposio-cli%2F@cf34758b5ee382025243d8cc6b0b8f7c0b4fa167
Security Audit — socket — Composio CLI