Connect Apps with Composio
ComposioHQ/awesome-claude-skills
Connects an agent to 1000+ external apps through the Composio Tool Router plugin, so it can actually send emails, create issues and post messages instead of only drafting them.
Show the app connection picker or setup widget when users ask to connect apps, reopen setup, or need an app that isn't connected yet.
$ npx skills add yc-software/qm --skill composio -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install yc-software/qm composio --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/yc-software/qm.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills-seed/composio .claude/skills/composio && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "composio" agent skill from https://github.com/yc-software/qm/tree/main/skills-seed/composio into .claude/skills/composio/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "composio", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/yc-software/qm/tree/main/skills-seed/composioType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add yc-software/qm --skill composio -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install yc-software/qm composio --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yc-software/qm.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills-seed/composio .agents/skills/composio && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "composio" agent skill from https://github.com/yc-software/qm/tree/main/skills-seed/composio into .agents/skills/composio/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "composio", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add yc-software/qm --skill composio -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install yc-software/qm composio --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yc-software/qm.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills-seed/composio .cursor/skills/composio && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "composio" agent skill from https://github.com/yc-software/qm/tree/main/skills-seed/composio into .cursor/skills/composio/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "composio", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/yc-software/qm.git --path skills-seed/composio--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add yc-software/qm --skill composio -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install yc-software/qm composio --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yc-software/qm.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills-seed/composio .gemini/skills/composio && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "composio" agent skill from https://github.com/yc-software/qm/tree/main/skills-seed/composio into .gemini/skills/composio/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "composio", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install yc-software/qm composioInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add yc-software/qm --skill composio -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/yc-software/qm.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills-seed/composio .github/skills/composio && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "composio" agent skill from https://github.com/yc-software/qm/tree/main/skills-seed/composio into .github/skills/composio/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "composio", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add yc-software/qm --skill composio -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install yc-software/qm composio --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/yc-software/qm.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills-seed/composio .opencode/skills/composio && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "composio" agent skill from https://github.com/yc-software/qm/tree/main/skills-seed/composio into .opencode/skills/composio/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "composio", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
composioShow the app connection picker or setup widget when users ask to connect apps, reopen setup, or need an app that isn't connected yet.
Composio is an agent skill from yc-software/qm. Show the app connection picker or setup widget when users ask to connect apps, reopen setup, or need an app that isn't connected yet. Use QM’s authenticated backend for app discovery, consent, and execution without exposing project keys.
Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Productivity & Automation, covering App automation through connectors. It works with Composio and Slack. The repository describes itself as: Multiplayer agent harness for work. The licence is MIT.
5 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 23af31b. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are javascript).
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
AGENT_API_TOKENFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Composio loads about 1.6k tokens when it runs. Until then it costs about 62 tokens; SKILL.md has 812 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from yc-software/qm at commit 23af31b, republished under its MIT licence (© yc-software). 812 words, ~1,551 tokens.
.claude/skills/composio/SKILL.md (or your agent's skills folder).Use this skill for app discovery, consent, and execution through QM's authenticated backend. Check availability with GET /v1/composio/toolkits; an absent sandbox API key is expected. Never ask regular users to provision a Composio project key.
When the user asks to connect apps, browse integrations, or show setup again in web chat, include the following directive as its own paragraph in your reply, with blank lines around it:
::connect-apps{}Write the directive directly, without a code fence or quotation. The web UI renders only the searchable app picker in place. To display the separate Add to Slack action, use ::add-to-slack{} as its own paragraph instead. Include both directives in separate paragraphs when the user asks for full setup. The Slack action is available to administrators; other users should ask their administrator to install QM. Do not repeat the welcome or celebration. Rendering the widget does not authorize any service or require an SDK call; the user chooses an app and completes provider consent. Do not claim accounts are connected without verified status. For Slack conversations, use ordinary authorization links instead of this web-only directive.
Check connections before work that depends on an app. If the app is in the catalog but not connected, ask for it in your first reply: do any part that doesn't need the app, show the connect option, and stop. Don't finish a long partial answer first.
toolkits lists it. In web chat, use ::link-slack-account{} as its own paragraph for personal Slack access or its connection status. Use ::add-to-slack{} for the separate administrator step of installing the workspace bot, which must be completed first. In Slack conversations, direct the user to QM web Settings (/?view=settings) and Link your Slack account, signed into their existing web account. Never use ::connect-apps{toolkit="slack"} or a generic Slack authorization link. These dedicated widgets do not automatically resume the task; ask the user to reply after connecting.::connect-apps{toolkit="notion"} on its own paragraph, using the exact id from toolkits. It shows a single connect button for that app. After consent the user returns to this conversation, the account is verified, and a message is sent so you can continue the task.authorize (step 3 below) and say you'll pick the task back up when they reply.Use the authenticated QM API from the computer through the normal execute tool. The Composio project key stays in QM's backend. Do not request it from the keychain, install the Composio SDK, use old SDK scripts, or call Composio directly. Existing execute approval and command policies still apply.
const base = process.env.AGENT_API_URL;
const token = process.env.AGENT_API_TOKEN;
async function apps(path, body) {
const response = await fetch(`${base}/v1/composio/${path}`, {
method: body === undefined ? "GET" : "POST",
headers: { "X-Agent-Capability": token, "Content-Type": "application/json" },
...(body === undefined ? {} : { body: JSON.stringify(body) }),
});
const result = await response.json();
if (!response.ok) throw new Error(JSON.stringify(result));
return result;
}apps("toolkits") and connected accounts with apps("connections"). Follow nextCursor using the cursor query parameter until exhausted. QM derives the account owner from the authenticated run; never supply another user ID.apps("tools?" + new URLSearchParams({toolkit: "gmail", query: "search emails"})). Use actual discovered slugs, input schemas, and concrete versions. Follow pagination. If several accounts match, ask which to use.apps("authorize", {toolkit: "gmail"}). Present the returned url to the user; they consent themselves. Poll connections afterward and only claim success once the returned account ID is listed. For personal Slack identity linking, use the web linking widget described in connect-apps instead of a generic Slack authorization link.apps("execute", {tool: discovered.slug, accountId: account.id, version: discovered.version, arguments: args}). No project key, user ID, custom authentication, raw proxy, or tool-router session is accepted. Inspect successful and error, not just the HTTP status. Never automatically retry an uncertain write.The API checks active account ownership and toolkit on every execution. Personal connections are available only in authorized contexts. Shared conversations require explicit sharing; unattended work needs its existing owner-keychain authorization. A denial is not permission to switch credentials, accounts, identities, or access paths.
Do not call Composio's callback completion API from the computer. Callback identity verification belongs to the signed-in browser and trusted QM backend. If verification setup is missing, ask the operator to fix it.
Automatic file transfer is unsupported. A local filename does not upload bytes. When Composio is unavailable, use direct OAuth only if independently configured and authorized; do not use it to bypass a denial.
© yc-software, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills-seed/composio of yc-software/qm.
Open the folder on GitHubat commit 23af31b
Composio next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Composio this skillyc-software/qm | 15k | — | ~1.6k | Automated safety check: Pass | MIT | |
| Connect Apps with ComposioComposioHQ/awesome-claude-skills | 77k | 3 repos | ~557 | Automated safety check: Pass | None | |
| Composio Cloud Toolsquarqlabs/argus | 277 | — | ~543 | Automated safety check: Pass | Apache-2.0 | |
| Setting Up RelayfileAgentWorkforce/relay | 865 | — | ~3.3k | Automated safety check: Pass | Apache-2.0 | |
| Slack Automationdavila7/claude-code-templates | 32k | 8 repos | ~2.4k | Automated safety check: Pass | MIT | |
| ComposioComposioHQ/composio | 30k | 1 repos | ~1.7k | Automated safety check: Pass | MIT |
ComposioHQ/awesome-claude-skills
Connects an agent to 1000+ external apps through the Composio Tool Router plugin, so it can actually send emails, create issues and post messages instead of only drafting them.
quarqlabs/argus
Routes requests to external SaaS apps such as GitHub, Gmail, Google Calendar, Slack, Notion and Linear through cloud tools, with safeguards on irreversible actions.
AgentWorkforce/relay
A skill your agent uses when an agent or human needs to set up relayfile end-to-end so agents can read and write provider files through a local mount.
davila7/claude-code-templates
Automate Slack workspace operations including messaging, search, channel management, and reaction workflows through Composio's Slack toolkit.
ComposioHQ/composio
Route and complete Composio work across Composio For You and Composio Platform.
melandlabs/openloomi
openloomi Connectors tools - manage the native 7 messaging integrations and pair with the composio skill for the 1000+ apps OAuth layer (Slack, Discord, X, Gmail, Outlook, Google…
yc-software/qm
Act for an org admin — the admin API (scope directory, per-scope config & SOUL, any scope's memory, transcripts & captured prompts, files, user roster & external users, audit/errors/metrics/egress)…
yc-software/qm
Drive a real stealth browser from your shell — act on websites (order food, file an expense, pull data behind a login), with per-person persistent sign-ins via the provider's managed auth (Kernel…
yc-software/qm
Run the current worktree as a production-shaped local dev instance with web, Slack, or both, on a real LLM + Postgres.
yc-software/qm
Work with GitHub and GitLab repositories through resident gh/glab/git auth on the agent computer.
yc-software/qm
Read and act on the user's Gmail, Google Calendar, and Google Tasks through per-user OAuth.
yc-software/qm
Deliberately search, add to, or curate your long-term memory with the memory tool — beyond the automatic recall/capture every turn already does.
Categories
Show the app connection picker or setup widget when users ask to connect apps, reopen setup, or need an app that isn't connected yet. Composio is an agent skill from yc-software/qm. Show the app connection picker or setup widget when users ask to connect apps, reopen setup, or need an app that isn't connected yet.
Composio fits situations like: tasks that involve App automation through connectors.
Run `npx skills add yc-software/qm --skill composio -a claude-code`. Or copy the skill folder (skills-seed/composio in yc-software/qm) into .claude/skills/composio in your project. Claude Code loads it when a task matches its description.
Run `npx skills add yc-software/qm --skill composio -a codex`. Or copy the skill folder (skills-seed/composio in yc-software/qm) into .agents/skills/composio in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add yc-software/qm --skill composio -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/composio, .gemini/skills/composio, .github/skills/composio and .opencode/skills/composio in your project.
Going by SKILL.md and its folder, Composio needs credentials named AGENT_API_TOKEN. Our summary lists: A credential in AGENT_API_TOKEN.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Composio is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.6k tokens (SKILL.md is roughly 6.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Composio: Connect Apps with Composio (ComposioHQ/awesome-claude-skills, 77k stars), Composio Cloud Tools (quarqlabs/argus, 277 stars), Setting Up Relayfile (AgentWorkforce/relay, 865 stars) and Slack Automation (davila7/claude-code-templates, 32k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
yc-software (a GitHub organization) maintains it in yc-software/qm, which has 15,357 GitHub stars. The repository holds 29 skills in this directory. The repository was last updated on October 6, 2026.
Source: yc-software/qm on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.