A leaked Composio key returned live Gmail, GitHub and CircleCI tokens

shimi121 pts0 comments

The Hidden Attack Surface of Agentic AI: Securing AI Agent Integration Platforms

Solutions

Resources

Company

CustomersPricing

Platform

Solutions

Resources

Company

Customers<br>Pricing

Back

Products

Capabilities

Services

Back

Industries

Solutions

Partnerships

Back

Resources

AI Security School

Back

About Cyera

About Us

Trust Center

Newsroom

Careers

Careers IL

Partners

Contact Us

Get a demo

Get a demo

The Hidden Attack Surface of Agentic AI: Securing AI Agent Integration Platforms

Assaf Morag<br>August 13, 2026

Share

As AI is widely adopted, the number of integrated tools and services is growing rapidly. As they grow, the AI integration layer has become a new, and increasingly complex, attack surface. Each new component introduces additional credentials, secrets, and trust relationships. As onboarding AI becomes easier, organizations need to better understand these risks. Unfortunately, most security teams have not mapped their AI integration layer.<br>Cyera researchers examined that layer across hundreds of organizations and found thousands of exposed credentials: API keys for Composio, Arcade, Nango, Tavily, Exa, LlamaIndex, Firecrawl, and other platforms that connect AI models to the enterprise systems they operate on. The owners were startup founders, CTOs, AI company executives, and enterprise software vendors across North America, Europe, Africa, and APAC. In several cases, the credentials belonged to the people responsible for building the AI systems they compromised.<br>One example: a VP of Engineering at a North American technology company committed a Composio API key to a public repository. Composio is an AI agent integration platform that provides a unified interface for connecting LLMs and autonomous agents to hundreds of third-party applications, APIs, and enterprise tools with managed authentication and action execution. Depending on the permissions associated, an attacker with such a key can gain almost full visibility into the organization's AI agent ecosystem and possibly the ability to execute downstream tools.<br>What the AI Integration Layer Actually Does<br>The AI stack has a gap between the model and the systems it needs to reach. An agent tasked to "find all Salesforce customers who opened support tickets last week, summarize the issues, and notify account managers in Slack" needs to authenticate to Salesforce, manage OAuth tokens, refresh expired credentials, connect to Slack, and execute actions across both applications. The integration layer handles that work.

Four categories of platform make up this layer:<br>Integration Infrastructure.  Platforms like Nango build and maintain hundreds of integrations to Salesforce, Slack, GitHub, and Google Workspace, handling API authentication, connectors, and OAuth workflows. They manage hundreds of APIs and authentication flows behind a single interface.<br>Unified Enterprise Data Layers.  Platforms like Merge unify vendors within a category. Dozens of HR software vendors, Workday, BambooHR, ADP, HiBob, each expose different APIs. Merge abstracts those differences so AI agents query HR data without maintaining separate integrations for each vendor.<br>AI-Native Search and Retrieval.  Platforms like Composio, Arcade, and Nango give AI agents search and retrieval capabilities: real-time web search, content extraction, and structured data retrieval. They are the primary mechanism through which agents gather external information and feed it into knowledge pipelines.<br>Agent Security and Governance.  Platforms like Arcade define what AI agents are permitted to do: delete records, access customer data, send emails, approve transactions, modify cloud resources, and so on. They broker authentication between agents and the services they operate on.<br>What Cyera Found<br>Cyera researchers identified its customers' AI integration infrastructure across hundreds of organizations. MCP servers represented the largest category by count. Across all categories, we observed tenants running thousands of sanctioned and unsanctioned applications. More than 10% of those applications were both unsanctioned and externally facing. Upon detection, our customers were alerted to mitigate and better secure their environments.

MCP Servers: Large Footprint, Low Visibility<br>MCP servers were the most prevalent category, with hundreds of tenants and thousands of deployments including Microsoft 365 MCP, Atlassian, and Notion integrations. Discovering an MCP server provides almost no information about its actual risk. A single MCP server can expose source code, internal documentation, cloud environments, customer data, or proprietary business systems. Knowing the server exists does not reveal what data it can access, what actions it can perform, or what an attacker gains by compromising it.<br>Agent Authentication and Governance<br>Cyera found dozens of organizations running platforms like Arcade and Composio, including 17 unsanctioned deployments. These platforms act as authentication...

integration platforms agent composio layer hundreds

Related Articles