composio-mcp
Pass
Audited by Gen Agent Trust Hub on Aug 3, 2026
Risk Level: SAFENO_CODE
Full Analysis
- [SAFE]: The skill consists exclusively of instructional content and does not include any executable scripts, binaries, or configuration files that could introduce code-based vulnerabilities.
- [PROMPT_INJECTION]: No evidence of prompt injection or bypass instructions was found. The instructions reinforce existing safety guidelines and tool usage protocols, explicitly forbidding the guessing of tool names or account IDs.
- [DATA_EXFILTRATION]: No sensitive file access or unauthorized network operations were detected. The skill correctly instructs the agent to keep secrets out of prompts and logs.
- [COMMAND_EXECUTION]: No dangerous shell commands or privilege escalation attempts were found. The skill relies on the Composio MCP for tool execution, which is an external, platform-managed layer, and explicitly warns against local installations.
- [EXTERNAL_DOWNLOADS]: The skill does not perform any external downloads or install third-party packages. It focuses on using already available MCP tools within the runtime environment.
Audit Metadata