Security audit
Composio
Security checks across malware telemetry and agentic risk
Overview
This plugin coherently connects OpenClaw to Composio so users can authorize their own external tools, with the sensitive access disclosed and scoped to that purpose.
Install only if you are comfortable giving this plugin an org-level Composio API key and allowing users to connect their own accounts through Composio OAuth. Connected external services such as email, Notion, GitHub, or Sentry can expose sensitive data to agent runs when users invoke those tools.
SkillSpector was not run because this plugin release contains no bundled skills.
VirusTotal
61/61 vendors flagged this plugin as clean.
Static analysis
No suspicious patterns detected.
