Who's Vetting Your AI Agent's Add-Ons?

As AI agents install skills and plugins on their own, a startup called AIR wants to police that new software supply chain before attackers do.

Who's Vetting Your AI Agent's Add-Ons?

Give an AI agent the keys to your company's systems, and it will happily start reaching for tools. A plugin here, a connector there, a fresh skill downloaded off the internet. The trouble is that almost nobody is checking what those tools actually do.

A security startup called AIR just came out of stealth with $50 million to fix that. Its bet is simple: the software agents install is starting to look like a supply chain, and supply chains need watching.

What it is

AIR was founded by Yair Saban and Niv Hoffman, both veterans of Israel's Unit 8200 intelligence corps, where they worked on offensive cybersecurity. Their platform does three things. It discovers the AI agents running inside a company, including ones set up by employees without IT's blessing. It hooks into those agents to intercept their actions, like loading a skill or pulling content from the web. And it checks whatever the agent wants to use against a whitelist AIR maintains.

A quick glossary. An MCP server, short for Model Context Protocol, is a standard way for agents to plug into external tools and data. A "skill" or add-on is a capability an agent can install to do something new. Think of them as apps for your AI.

Why it matters

Saban reaches for a tidy analogy. In the early 2000s, you could install a driver on your computer without any signature saying who made it. Today drivers are signed, because they load code deep into your system. Agent skills and plugins work through a similar mechanism, he argues, but they arrive with no such check.

The specific worry is subtle. Instead of attacking an agent head-on, an attacker can poison the content the agent reads, or tamper with a package that a previously safe skill quietly downloads. A tool that passed inspection last week can turn hostile this week if its developer's account gets compromised. AIR says it currently filters out roughly 27% of the add-ons and skills it finds online, a striking share if it holds up.

As Sequoia's Bogomil Balkansky put it, this is not a scanning problem, it is a continuous re-verification problem. Inspect every skill and MCP server an agent touches, then re-inspect each one every time it changes, in real time, across a whole fleet of agents. That is more of a plumbing challenge than a security one.

The money and the crowd

The $50 million came in two seed rounds that closed within weeks of each other. Sequoia led a first $10 million round, and Greenoaks led a second $40 million round. A long list of angels joined, including Wiz co-founder Yinon Costica and Cognition president Zach Frankel. AIR says it has more than 20 customers, about a quarter of them large enterprises, with the strongest interest coming from regulated fields like financial services and pharmaceuticals.

AIR is not alone. Noma Security, Zenity, Astrix Security, and Operant AI all sell overlapping tools for discovering and governing agents and MCP servers. The category is well funded too. Zenity raised a $125 million Series C in August, and Noma pulled in $100 million last year. Saban argues AIR's edge is the continuous vetting of the skills ecosystem, not the discovery piece, which he thinks everyone will be able to do.

What's next

The new capital will mostly fund researchers and a U.S. and European sales push for the roughly 40-person team. One open question hangs over the whole category. Saban concedes that AI labs will eventually bake security checks into their own platforms. He is betting companies will still want an independent referee that works across every vendor. Whether that bet pays off depends on how fast the big model providers decide to police their own app stores.

Subscribe to BuzzBelow

Don’t miss out on the latest issues. Sign up now to get access to the library of members-only issues.
jamie@example.com
Subscribe