deploy-pipeline
Warn
Audited by Socket on Apr 24, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: The skill's functionality broadly matches its stated deployment purpose, but it concentrates multiple high-impact production actions and linked service credentials inside the Composio CLI/platform. The install path appears official and same-org, so this is not confirmed malware, yet the third-party credential forwarding and autonomous prod changes make it a high operational/security-risk skill.
Confidence: 87%Severity: 72%
Audit Metadata