Composio
CAUTION: May 21, 2026 security incident — attacker chained compromised employee Gmail OAuth into an internal agentic tool and achieved arbitrary code execution in the tool-execution sandbox, exposing 5,000+ GitHub connections and ~5,241 API keys; Composio engaged external IR, rev
Dimension breakdown
Score · confidenceMay 21, 2026 security incident — attacker chained compromised employee Gmail OAuth into an internal agentic tool and achieved arbitrary code execution in the tool-execution sandbox, exposing 5,000+ GitHub connections and ~5,241 API keys; Composio engaged external IR, revoked all GitHub tokens, mandated API-key rotation (<3hr notice), and added IP allowlisting.
Agentic integration platform: MCP Gateway with 1,000+ toolkits, team SSO/allowlisting, managed OAuth. SOC 2 Type II + ISO 27001 hold and training opt-out is now explicit; Tool Router graduated Beta→GA (stable 'sessions').
But the breach (plus an April 28 webhook outage and Feb 9 incident) is a severe trust hit in Composio's core credential-handling surface, and competitors (Nango, Pipedream) now cite it as a differentiator. Managed-only (no broad self-host).
Monitor for: completed Zero-Trust KMS remediation, sustained sentiment recovery, independent post-incident audit.
Use cases
Not yet assessed — this section fills in as ACES research covers the tool.
Risk flags
Severe negative sentiment
trustTemporaryWidespread negative sentiment (sentiment score 1-2)
Removed when — Sustained sentiment improvement over 90+ days with community acknowledgment of fixes
Status rationale
Tracked maintained — and held there by the severe-negative-sentiment cap (max signal level Tracked). The May 21, 2026 sandbox arbitrary-code-execution breach (5,000+ GitHub connections, ~5,241 API keys), an April 28 webhook outage, and the Feb 9 incident are a material trust failure in Composio's core credential-handling surface that blocks advancement to Assessed, despite remediation (external IR, token revocation, key rotation, IP allowlisting, KMS roadmap) and positives (Tool Router GA, explicit training opt-out, SOC 2 Type II + ISO 27001).
Incident was contained/remediated, so no critical-security-vuln dimension cap; the impact is reflected as Compliance −12 within band.
Movement triggers
Upgrade if: Zero-Trust Proxy KMS remediation ships and is independently verified, post-incident security audit published, community/enterprise sentiment recovers over 90+ days with no new incidents, independent F500 enterprise references confirmed, or self-hosted/data-residency option broadly available. Downgrade if: a new unpatched CVE or repeat breach surfaces, incident remediation stalls, community exodus toward Nango/Pipedream/native MCP servers materializes, funding concerns appear, or development velocity stalls (>90 days without changelog entry).
Risks & limitations
Severe Negative Sentiment
ModerateRadar cap: severe-negative-sentiment
Integration surface
Not yet assessed — this section fills in as ACES research covers the tool.
Adoption & benchmarks
Not yet assessed — this section fills in as ACES research covers the tool.
Spotted something wrong or missing here? Suggest a change →
Per-source contributions
Click any dimension to see the underlying sources and citations.
More in this category