composio

Warn

Audited by Socket on Jul 15, 2026

1 alert found:

Anomaly
AnomalyLOW
SKILL.md

SUSPICIOUS. The skill is broadly aligned with its purpose as an official Composio integration/router, and the installer appears same-org and documented rather than a random payload. However, it combines a pipe-to-shell install, third-party credential centralization, intermediary routing of app actions/auth through Composio, transitive skill installation, and high-impact cross-app actions. This is better classified as a high-trust integration skill with meaningful security risk, not confirmed malware.

Confidence: 85%Severity: 68%
Audit Metadata
Analyzed At
Jul 15, 2026, 12:54 PM
Package URL
pkg:socket/skills-sh/Lua2147%2Fclaude-toolkit-catalog%2Fcomposio%2F@62a8d0f5c6a7cf601d965f34272bd2f2115a5f6b8f0d4db286bb75a404819c39
Security Audit — socket — composio