composio
Warn
Audited by Socket on Apr 1, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill's purpose broadly matches SaaS integration, but its actual data flow routes all actions through a custom Fly-hosted gateway over plain HTTP rather than Composio's documented public API. That proxy architecture expands trust boundaries, centralizes delegated credentials/actions, and enables high-impact real-world operations across many apps, making the overall risk medium-high despite low classic supply-chain risk.
Confidence: 87%Severity: 76%
Audit Metadata