Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsCommunityBlog
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

Back to skills

Composio

CSecurity

Use 1000+ external apps via Composio - either directly through the CLI or by building AI agents and apps with the SDK

1,019 stars
0 votes
0 copies
1 views
Added 9/5/2026
ai-agentsshellbashgitapibackend

Works with

terminalcliapimcp

Security Analysis

C71/100
criticalPipes output to a shell interpreter
mediumUses curl or wget to download content
criticalDownloads and executes remote scripts — classic supply chain attack

Scanned 9/5/2026

Install to Claude Code

$npx -y skills add melandlabs/openloomi --skill composio --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Composio?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Composio
[![Security: C — Skills Directory](https://www.skillsdirectory.com/api/skills/melandlabs-composio-openloomi/badge)](https://www.skillsdirectory.com/skills/melandlabs-composio-openloomi)

More formats (shields.io, HTML) on the badges page.

Download Zip
Files
SKILL.md
---
name: composio
description: Use 1000+ external apps via Composio - either directly through the CLI or by building AI agents and apps with the SDK
tags: [composio, tool-router, agents, mcp, tools, api, automation, cli]
---

## When to Apply

- User wants to access or interact with external apps (Gmail, Slack, GitHub, Notion, etc.)
- User wants to automate a task using an external service (send email, create issue, post message)
- Building an AI agent or app that integrates with external tools
- Multi-user apps that need per-user connections to external services

## Setup

Check if the CLI is installed; if not, install it:
```bash
curl -fsSL https://composio.dev/install | bash
```

After installation, restart your terminal or source your shell config, then authenticate:
```bash
composio login       # OAuth; interactive org/project picker (use -y to skip)
composio whoami      # verify org_id, project_id, user_id
```
For agents without direct browser access: `composio login --no-wait | jq` to get URL/key, share URL with user, then `composio login --key <cli_key> --no-wait` once they complete login.

---

### 1. Use Apps via Composio CLI

**Use this when:** The user wants to take action on an external app directly — no code writing needed. The agent uses the CLI to search, connect, and execute tools on behalf of the user.

Key commands (new top-level aliases):
- `composio search "<query>"` — find tools by use case
- `composio execute "<TOOL_SLUG>" -d '{...<input params>}'` — execute a tool
- `composio link [toolkit]` — connect a user account to an app (agents: always use `--no-wait` for non-interactive mode)
- `composio listen` — listen for real-time trigger events

Typical workflow: **search → link (if needed) → execute**

> Full reference: [Composio CLI Guide](rules/composio-cli.md)

---

### 2. Building Apps and Agents with Composio

**Use this when:** Writing code — an AI agent, app, or backend service that integrates with external tools via the Composio SDK.

Run this first inside the project directory to set up the API key:
```bash
composio init
```

> Full reference: [Building with Composio](rules/building-with-composio.md)

---

## Sandbox and network

Composio operations are network-heavy: CLI install, OAuth login, tool search,
tool execution, and trigger subscriptions all make outbound calls. If any of
these fail with a network error (`ECONNREFUSED`, `ETIMEDOUT`, "unreachable",
or a hung login), check whether Codex is running inside a sandbox before
declaring the install or login broken. Codex sandboxing can block:

- `curl -fsSL https://composio.dev/install | bash` (and the post-install
  binary download from Composio's CDN).
- `composio login` (OAuth redirect, browser handoff, and token exchange).
- `composio execute`, `composio search`, and `composio listen` (calls to
  Composio's tool-router and the 1000+ external app APIs).
- `mcp__composio__*` MCP tool calls and `COMPOSIO_REMOTE_BASH_TOOL` /
  `COMPOSIO_REMOTE_WORKBENCH` if outbound network is sandboxed.

Request approval and retry the same command outside the sandbox. If the
outside-sandbox retry succeeds, treat the in-sandbox failure as a sandbox
artifact and continue. Do not report that the install URL is invalid, the
auth flow is broken, or a remote app is unreachable until the outside-sandbox
retry also fails. For agents without direct browser access, `composio login
--no-wait | jq` is the recommended handoff — make sure that pattern is not
swallowed by the sandbox.

Attribution

melandlabsmelandlabs
View sourceMore from melandlabs →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Caveman

Ultra-compressed communication mode that cuts output tokens while keeping technical accuracy. Levels: lite, full, ultra and the wenyan variants. Use for /caveman, "caveman mode", "talk like caveman", "be brief" or "less tokens".

1066601 votes

Hyperplan

Adversarial multi-agent planning skill. Self-orchestrates 5 hostile category members (unspecified-low, unspecified-high, deep, ultrabrain, artistry) via team-mode for ruthless cross-critique debate, distills only the defensible insights, then MANDATORILY hands the distilled insight bundle to the `plan` agent for executable plan formalization. Use when planning needs maximum rigor and surfacing of weak assumptions, blind spots, and over-engineering. Triggers: 'hyperplan', 'hpp', '/hyperplan', ...

686011 votes

Mcp Code Execution

Routes multi-tool workflows through MCP servers for large datasets and pipelines. Use when Bash tool overhead is limiting throughput on data-heavy tasks.

3351 votes

catchup

Recovers the conversation and failed tool calls of a previous Codex, Claude Code, Antigravity, Cline, Copilot CLI, Cursor, DeepSeek Harness, Kimi, OpenCode, Pi Agent, or ZCode session. Use when the user says "catch up", "what did the last session do", "get me up to speed", "I switched agents", asks to recover/summarize a previous session before continuing, or asks to diagnose or report a catchup failure. Do NOT use for the current conversation, git history, or any non-agent log.

651 votes

math-skill

A comprehensive mathematical reasoning skill for AI assistants — handles arithmetic to research-level problems with rigorous step-by-step reasoning, systematic verification, and transparent uncertainty handling

381 votes
View all in ai-agents →