Composio

Security checks across malware telemetry and agentic risk

Overview

This looks like a legitimate Composio integration, but it gives an agent broad power to act across connected apps and run persistent remote code, so users should review it carefully before installing.

Install only if you intentionally want your agent to use Composio across third-party apps. Use a dedicated Composio project, connect only the accounts needed, review OAuth scopes, keep the API key private, require explicit confirmation before sending, posting, editing, deleting, uploading, or running code, and revoke connections when the task is finished.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The skill explicitly enables execution of arbitrary Python and bash in a persistent remote sandbox, including helper functions that can call external services and connected apps. Even if intended for legitimate automation, presenting these capabilities without strong safety gates, user-consent requirements, or warnings about destructive/system-impacting actions materially increases the chance of harmful execution, data exfiltration, or lateral abuse through connected accounts.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal