leiga-automation
Warn
Audited by Socket on Mar 29, 2026
1 alert found:
AnomalyAnomalySKILL.md
LOWAnomalyLOW
SKILL.md
SUSPICIOUS: The skill's purpose matches Leiga automation, and the referenced MCP service is plausibly official Composio infrastructure, so this is not confirmed malware. However, it routes all tool discovery, connection handling, and execution through a hosted intermediary, and it understates credential requirements with 'No API keys needed' even though Leiga auth is managed upstream. The main risk is third-party mediation of actions and data, not overtly malicious behavior.
Confidence: 85%Severity: 58%
Audit Metadata