composio-mcp

Warn

Audited by Socket on Aug 4, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS: The skill is largely consistent with Composio's documented hosted MCP product and shows no obvious malware or rogue installer behavior, but it routes external-service access through an intermediary, includes remote shell/Python execution, and enables broad autonomous cross-app actions. Risk is driven by centralized credential/data handling and action scope rather than confirmed malicious intent.

Confidence: 86%Severity: 68%
Audit Metadata
Analyzed At
Aug 4, 2026, 04:43 PM
Package URL
pkg:socket/skills-sh/ComposioHQ%2Fcomposio-mcp-plugin%2Fcomposio-mcp%2F@e5b1274614b5fe74cbe291aca510272e89b8608ac10d791bf1c66d5310e868da
Security Audit — socket — composio-mcp