composio

Warn

Audited by Socket on May 11, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: the stated purpose matches SaaS integration, but the implementation routes all data and actions through a custom gateway that is not an official documented Composio API path, uses plain HTTP on an internal network, and enables broad autonomous real-world actions. This looks more like a powerful internal integration proxy than malware, but its trust model, intermediary data flow, and action scope create significant security risk.

Confidence: 89%Severity: 84%
Audit Metadata
Analyzed At
May 11, 2026, 10:31 AM
Package URL
pkg:socket/skills-sh/Starchild-ai-agent%2Fofficial-skills%2Fcomposio%2F@4b830d10dca4dac0a5a95772cbaa161615827fb0