composio-mcp

Pass

Audited by Gen Agent Trust Hub on Aug 3, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill consists exclusively of instructional content and does not include any executable scripts, binaries, or configuration files that could introduce code-based vulnerabilities.
  • [PROMPT_INJECTION]: No evidence of prompt injection or bypass instructions was found. The instructions reinforce existing safety guidelines and tool usage protocols, explicitly forbidding the guessing of tool names or account IDs.
  • [DATA_EXFILTRATION]: No sensitive file access or unauthorized network operations were detected. The skill correctly instructs the agent to keep secrets out of prompts and logs.
  • [COMMAND_EXECUTION]: No dangerous shell commands or privilege escalation attempts were found. The skill relies on the Composio MCP for tool execution, which is an external, platform-managed layer, and explicitly warns against local installations.
  • [EXTERNAL_DOWNLOADS]: The skill does not perform any external downloads or install third-party packages. It focuses on using already available MCP tools within the runtime environment.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 3, 2026, 02:54 PM
Security Audit — agent-trust-hub — composio-mcp