This release appears healthy and suitable to depend on. It has a strong release cadence with 135 releases and 60 releases in the last 12 months, is not deprecated, and is backed by an active organization-owned repository with 859 commits and 56 active maintainers over the last 3 months. The package has an explicit ISC license, TypeScript declarations, no install-time lifecycle scripts, zero runtime dependencies, npm provenance attestation, repository tests and changelog coverage, and substantial security and workflow hygiene. The main limitations are that the published artifact is minimal and lacks packaged tests and a changelog, while repository commit activity is somewhat concentrated in one contributor; these are substantially mitigated by the large active contributor base, organization backing, and repository-level documentation and tests.
92%
Total Score
100
100
95
90
100
Most analyzed workflows have read-only permissions, but one lacks top-level permissions and two declare top-level write access, leaving a modest workflow-permission hygiene concern.
Version 0.12.2 is not a stable-major release, so API compatibility may still evolve, but it is not a prerelease and recent prereleases comprise only 5% of releases.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-511457 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @composio/openai is vulnerable to Insertion of Sensitive Information into Log File in versions 0.1.36 - 0.12.1. | 0.1.36 - 0.12.1 | Low |
No direct dependencies.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.