## Summary - write CLI user data, pending login sessions, and agent identities through one atomic `0600` helper - repair `0644` credential files created by older CLI versions before reading them - redact credential-shaped structured values from CLI user-context diagnostics - redact secret-shaped text at both TypeScript and Python SDK log-output boundaries, including Pusher `auth` responses and exception tracebacks - preserve Python logger compatibility: errors remain untruncated, disabled levels remain lazy, and malformed placeholders cannot expose arguments ## Local reproduction Under the normal `022` umask, `next` created a plaintext credential file with mode `0644`. The pre-fix CLI user-context and TypeScript SDK debug paths also emitted sentinel credentials. The private atomic writer changes an existing `0644` target to `0600`, and the upgrade tests now prove all three legacy credential files are tightened without changing their contents. ## Verification - CLI permission upgrade tests: 31 passed across user data, pending login, and agent identity paths - CLI source and test typechecks passed - TypeScript core logging, redaction, and Pusher tests: 17 passed - TypeScript core source and type-test typechecks passed - Python logging regression tests: 5 passed - focused Ruff, Prettier, Oxlint, and `git diff --check` passed The focused CLI runner needed a temporary local alias for the pre-existing missing `#ssrf_guard` mapping in the CLI Vitest config. The alias was removed after verification and is not part of this PR. ## Contributor context Credit to **Syed Anas Mohiuddin**, independent security researcher, for reporting the legacy CLI credential-file permission issue. Supersedes [#4300](https://github.com/ComposioHQ/composio/pull/4300) · [Glen review](https://app.tryglen.com/ComposioHQ/composio/pull/4300). The implementation also covers agent credentials, retains atomic writes, and applies redaction at the shared SDK logging boundary.
Composio TypeScript workspace
This directory contains the TypeScript half of the Composio SDK monorepo: the core SDK, provider adapters, the CLI, examples, and end-to-end tests. For an overview of Composio itself, start at the root README and docs.composio.dev.
If you just want to use the SDK:
npm install @composio/core
import { Composio } from '@composio/core';
const composio = new Composio({ apiKey: process.env.COMPOSIO_API_KEY });
const session = await composio.create('user_123');
const tools = await session.tools();
See the @composio/core README and the quickstart for the full flow, including provider setup for your agent framework.
Packages
Published packages:
| Package | Description |
|---|---|
@composio/core |
The Composio SDK. Ships its TypeScript source and SDK docs so installed copies are inspectable by coding agents. |
@composio/slim |
Same API as @composio/core without the packaged source and docs; smaller install. |
composio CLI |
Standalone CLI binary: search, execute, and script tools from your shell. |
@composio/* providers |
Adapters that format Composio tools for agent frameworks (OpenAI, Anthropic, Vercel AI SDK, LangChain, and more). See the provider table. |
@composio/experimental |
Experimental integrations, currently the Pi provider. |
@composio/json-schema-to-zod |
JSON Schema to Zod conversion. |
Internal (unpublished) packages: cli-keyring and cli-local-tools support the CLI; ts-builders generates TypeScript source.
Layout
ts/
packages/ Published and internal packages (see above)
examples/ Runnable examples per feature and framework
e2e-tests/ Runtime E2E tests (Node, Deno, Cloudflare Workers, CLI)
docs/ Workspace SDK docs: API notes and internal guides
scripts/ Build, validation, and scaffolding scripts
vendor/ Read-only reference submodules; do not edit
Development
Commands run from the repository root. Install the pinned toolchain first:
mise install
pnpm install
Build and verify:
pnpm build:packages # build all TS packages
pnpm typecheck # typecheck all TS packages
pnpm lint:packages # oxlint over ts/packages
pnpm test # package unit tests plus example validation
Runtime E2E suites (require credentials):
pnpm test:e2e:node
pnpm test:e2e:deno
pnpm test:e2e:cloudflare
pnpm test:e2e:cli
Scaffolding:
pnpm create:provider <name> [--agentic] # new provider package
pnpm create:example <name> # new example under ts/examples
Changesets are required for changes to published packages; see the contribution guidelines.