Security audit
Composio
Security checks for vulnerabilities and agentic risk
Overview
This plugin connects OpenClaw to Composio using disclosed per-user OAuth sessions and does not show hidden or unrelated behavior.
Install only if you intend to let users connect Composio-backed accounts through OpenClaw. Admins should protect the org Composio API key, understand which Composio tools are enabled for users, and account for the documented session cache and media-file handling.
SkillSpector was not run because this plugin release contains no bundled skills.
Static analysis
No suspicious patterns detected.
