composio

Warn

Audited by Socket on May 22, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The stated purpose matches broad SaaS automation, but the skill's actual footprint is too expansive and intermediary-heavy: all actions are funneled through a non-official gateway over plain HTTP, it enables autonomous external actions like email and social posting, and one flow instructs reading a raw COMPOSIO API key from a local .env and sending it to third-party SDK/API endpoints. This is not confirmed malware, but it poses high security risk and weak data-flow integrity.

Confidence: 90%Severity: 87%
Audit Metadata
Analyzed At
May 22, 2026, 03:34 PM
Package URL
pkg:socket/skills-sh/Starchild-ai-agent%2Fofficial-skills%2Fcomposio%2F@2e01d6f259524fbc26fc5e6eee38aa7a57378b37