Back to skill

Security audit

Composio Integration

Security checks for vulnerabilities and agentic risk

Overview

The skill exposes a plaintext Composio API key and enables broad Gmail and Google Tasks actions through unscoped executors, so it needs Review before installation.

Do not install this as-is. Treat the Composio key as exposed, revoke and rotate it, remove personal account identifiers from the skill, and add allowlists plus explicit confirmation for sending, deleting, or modifying Gmail and Google Tasks data before publishing or using it.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T09 · Insecure Skill Coding Practices

Error
Location
SKILL.md:7
Finding

Hard-Coded Composio API Credential and Personal Account Metadata

Content
View full analysis
Remediation
View remediation
" ``` 4. Store credentials in a dedicated secret manager or another access-controlled credential store rather than documentation or shell startup files. 5. If environment variables remain necessary, inject them only into the specific process that needs them rather than globally exporting them from `~/.bashrc`. 6. Create a narrowly scoped credential limited to the required Gmail and Google Tasks operations. 7. Review Composio audit logs for use of the exposed key and investigate unexpected tool executions. 8. Add automated secret scanning and pre-commit checks to prevent future credential commits. ]]>

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/execute-tool.mjs:5
Finding

Unrestricted Dispatcher Executes Caller-Selected Actions with a Privileged API Key

Content
View full analysis
'' const [tool_slug, connected_account_id, argsJson] = process.argv.slice(2); if (!tool_slug || !connected_account_id) { console.error('Usage: node execute-tool.mjs \'\''); console.error('\nExample:'); console.error(' node execute-tool.mjs gmail_search_email aa5460b3-4171-4a38-a3c2-791abb3849ec \'{"maxResults":5}\''); process.exit(1); } const args = argsJson ? JSON.parse(argsJson) : {}; console.log(`🚀 Executing: ${tool_slug}`); console.log(`📎 Account: ${connected_account_id}`); console.log(`📋 Args: ${JSON.stringify(args, null, 2)}\n`); executeTool(tool_slug, { user_id: 'sid-main', connected_account_id, arguments: args }) .then(result => { console.log('✅ Success!\n'); console.log(JSON.stringify(result, null, 2)); }) .catch(err => { console.error('❌ Error:', err.message); process.exit(1); }); ``` The shell wrapper exposes similar functionality: ```bash APP="$1" ACTION="$2" PARAMS="${3:-{}}" RESPONSE=$(curl -s -X POS ...[truncated 2467 chars]
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Note
Location
scripts/execute-tool.mjs:37
Finding

Complete Tool Arguments and Remote Responses Are Written to Standard Output

Content
View full analysis
{ console.log('✅ Success!\n'); console.log(JSON.stringify(result, null, 2)); }) ``` The Gmail test script also prints the entire parsed response: ```javascript res.on('end', () => { console.log(JSON.stringify(JSON.parse(responseData), null, 2)); }); ``` The shell action wrapper does the same: ```bash echo "✅ Success!" echo "" echo "$RESPONSE" | jq '.' ``` ### Technical Analysis The executors print complete caller-supplied arguments and complete API responses without filtering or redaction. Gmail arguments may include recipients, subjects, bodies, or search terms. Responses may contain message content, sender and recipient addresses, task descriptions, identifiers, or other personal data. Standard output is frequently captured by agent transcripts, CI/CD systems, process supervisors, shell redirection, or centralized logging services. As a result, data retrieved with legitimate authorization can be copied into systems with broader access and longer retention periods. ### Attack Path 1. A user or agent invokes a Gmail retrieval, search, send, or another data-bearing action. 2. The request arguments or API response contain confidential information. 3. The script serializes the complete object and writes it to standard output. 4. A transcript, CI log, monitoring agent, redirected file, or terminal recording captures the output. 5. Another user or se ...[truncated 557 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The skill documentation directly exposes a live API key, its storage locations, and linked account identifiers. This gives anyone who can read the file immediate authenticated access to Gmail and Google Tasks capabilities, enabling account misuse, data theft, and unauthorized actions without any additional compromise.

Content

No source excerpt is available for this finding.

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 51)May include surrounding context.

md
node scripts/list-tools.mjs gmail # Gmail tools only

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 52)May include surrounding context.

md
node scripts/list-tools.mjs gmail # Gmail tools only

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 53)May include surrounding context.

md
node scripts/list-tools.mjs gmail # Gmail tools only

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill advertises broad access to 600+ third-party apps and already-connected Gmail and Google Tasks accounts, including read, send, delete, and task management operations. This exceeds a narrowly scoped purpose and increases blast radius: if the skill or its credentials are misused, an attacker can perform extensive cross-account actions affecting privacy, integrity, and availability.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The skill lists destructive and privacy-impacting operations such as reading inbox contents, sending email, deleting messages, and deleting tasks, but provides no explicit warning, consent guidance, or safety boundaries. In an agent context, this omission makes accidental or socially engineered misuse more likely because operators are not clearly alerted to sensitive actions.

Content

No source excerpt is available for this finding.

Unrestricted Tool Access

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Documenting an execute-tool.mjs script that can execute any tool indicates effectively unrestricted invocation of the connected Composio actions. Given the same skill also exposes valid credentials and broad connected-account capabilities, this materially increases the likelihood of unauthorized email sending, deletion, data access, or other arbitrary third-party operations.

Content

Scanner excerpt · SKILL.md (reported line 96)May include surrounding context.

text
/home/sidharth/clawd/skills/composio-integration/scripts/
├── list-tools.mjs       # List available tools
├── execute-tool.mjs     # Execute any tool
└── (future scripts)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script directly executes arbitrary Composio actions against a remote service with user-supplied app, action, and JSON parameters, but provides no confirmation, dry-run mode, allowlist, or warning about potentially destructive side effects. In an agent-skill context, this increases risk because actions may modify external systems such as email, calendars, or documents immediately once invoked.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The script transmits user-controlled action names and parameters, along with a privileged API key, to an external API endpoint. While external transmission is expected for this integration, it is still security-relevant because sensitive data in PARAMS may be exfiltrated to a third-party service and arbitrary remote actions can be triggered without local policy checks.

Content

Scanner excerpt · scripts/composio-action.sh (reported line 33)May include surrounding context.

sh
echo ""

# Execute the action via Composio API
RESPONSE=$(curl -s -X POST "https://backend.composio.dev/api/v1/actions/$ACTION/execute" \
  -H "X-API-Key: $COMPOSIO_API_KEY" \
  -H "Content-Type: application/json" \
  -d "{\"input\": $PARAMS}")

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script prints the full Gmail search API response directly to stdout, which can expose email metadata or message content to terminal logs, CI/CD logs, shell history capture tools, or other monitoring systems without any warning or redaction. Because the query is empty and the connected account is hardcoded, the script may retrieve recent emails broadly and disclose potentially sensitive mailbox data during routine testing or automation.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.env_credential_access, suspicious.exposed_secret_literal

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/execute-tool.mjs:3

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/list-tools.mjs:3

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
SKILL.md:50