Composio CLI
Warn
Audited by Socket on May 16, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: the skill's broad SaaS-action purpose matches its capabilities, and the installer appears to be the publisher's official path, so this is not clearly malicious. However, it carries meaningful security risk from same-org `curl|bash` installation, centralized credential forwarding through Composio's backend, and default transitive skill installation during login.
Confidence: 87%Severity: 56%
Audit Metadata