Back to plugin

Security audit

Composio

Security checks for vulnerabilities and agentic risk

Overview

This plugin connects OpenClaw to Composio using disclosed per-user OAuth sessions and does not show hidden or unrelated behavior.

Install only if you intend to let users connect Composio-backed accounts through OpenClaw. Admins should protect the org Composio API key, understand which Composio tools are enabled for users, and account for the documented session cache and media-file handling.

SkillSpector was not run because this plugin release contains no bundled skills.

Static analysis

No suspicious patterns detected.