connect-apps

Fail

Audited by Socket on Feb 16, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

[Skill Scanner] Natural language instruction to download and install from URL detected Benign in intent with a standard integration pattern, but requires explicit security controls in implementation: scoped permissions, secure storage and rotation of API keys/tokens, robust auditing, and clear user consent. The design should avoid hardcoded secrets and ensure least privilege across all connected apps. LLM verification: This skill's README describes a legitimate-sounding managed integration (Composio Tool Router) that enables an AI agent to act across many apps. The primary security concern is architectural: sensitive OAuth tokens and user data are centralized at a third-party service (Composio) without published implementation or security details in the artifact. There is no direct evidence in the provided text of obfuscated or malicious code, hard-coded secrets, or active exfiltration. However, because of the

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 16, 2026, 01:03 PM
Package URL
pkg:socket/skills-sh/frostant%2Fawesome-claude-skills%2Fconnect-apps%2F@19ae0e46ce260c0f1f45c5475fa898b62cdced46