deploy-pipeline

Warn

Audited by Socket on Apr 24, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill's functionality broadly matches its stated deployment purpose, but it concentrates multiple high-impact production actions and linked service credentials inside the Composio CLI/platform. The install path appears official and same-org, so this is not confirmed malware, yet the third-party credential forwarding and autonomous prod changes make it a high operational/security-risk skill.

Confidence: 87%Severity: 72%
Audit Metadata
Analyzed At
Apr 24, 2026, 07:32 PM
Package URL
pkg:socket/skills-sh/ComposioHQ%2Fawesome-codex-skills%2Fdeploy-pipeline%2F@36bcd1ebd44b47f41edc06f0b1b0ae6f034808cf