Trust Assessment
connect-apps received a trust score of 85/100, placing it in the Mostly Trusted category. This skill has passed most security checks with only minor considerations noted.
SkillShield's automated analysis identified 1 finding: 0 critical, 1 high, 0 medium, and 0 low severity. Key findings include Skill enables broad access to 1000+ external applications.
The analysis covered 4 layers: Manifest Analysis, Static Code Analysis, Dependency Graph, LLM Behavioral Safety. All layers scored 70 or above, reflecting consistent security practices.
Last analyzed on February 20, 2026 (commit 27904475). SkillShield performs automated 4-layer security analysis on AI skills and MCP servers.
Layer Breakdown
Behavioral Risk Signals
Security Findings1
| Severity | Finding | Layer | Location | |
|---|---|---|---|---|
| HIGH | Skill enables broad access to 1000+ external applications The `connect-apps` skill, through the `composio-toolrouter` plugin, is designed to connect Claude to over 1000 external applications, enabling a wide range of actions such as sending emails, creating GitHub issues, posting to Slack, and modifying data in various services. While this is the intended functionality, it grants the LLM extremely broad capabilities across a vast array of potentially sensitive user accounts and data. A successful prompt injection attack against the LLM could lead to unauthorized actions being performed across these connected services, potentially resulting in data manipulation, unauthorized communication, or service disruption. Implement strict access control and least privilege principles within the `composio-toolrouter` plugin, ensuring that only necessary permissions are requested and granted. Utilize granular OAuth scopes where available. Implement robust prompt injection defenses for the LLM to prevent unauthorized use of these broad capabilities. Users should be fully informed about the scope of permissions granted to the skill and the potential impact of its misuse. | LLM | SKILL.md:3 |
Scan History
Embed Code
[](https://skillshield.io/report/2a1aa976ab8fbe44)
Powered by SkillShield