Article is online

AIR Secures $50M to Vet and Monitor Skills, Plugins, and Add-Ons Used by AI Agents

AIR Secures $50M to Vet and Monitor Skills, Plugins, and Add-Ons Used by AI Agents

Table of Contents




You might want to know


How are companies beginning to secure the expanding software supply chain around AI agents?


What approach can continuously detect and re-evaluate the skills, plugins, and add-ons AI agents rely on?



Main Topic


As enterprises increasingly grant AI agents access to internal systems and external resources, a new software supply chain is forming around the tools those agents use: skills, plugins, MCP servers, and various add-ons that enable web access and integrations. This emergent ecosystem introduces fresh attack surfaces because agents can load third-party components into operational contexts, execute actions across databases and services, and fetch external content. The primary concern is not only direct exploitation of an agent but also poisoning or manipulating the inputs and components the agent consumes. That creates a need for visibility, continuous validation, and enforced controls across an organization’s agent fleet.



AIR, an AI security startup founded by Yair Saban (CEO) and Niv Hoffman (CTO), recently emerged from stealth with $50 million in seed funding across two closely timed rounds. The company’s platform focuses on three integrated capabilities: discovery of agents running across an enterprise environment, continuous vetting of the skills and add-ons those agents use, and enforcement controls that prevent agents from interacting with resources that fail security criteria. AIR also operates a marketplace of vetted skills and plugins to simplify safe consumption by enterprise agents.



The founders bring background in offensive cybersecurity from Israel’s Unit 8200, which shapes the company’s emphasis on proactive discovery and rigorous validation. In practice, AIR’s product aims to locate agents (including those started by employees using unapproved accounts), monitor agent behavior at runtime, and intercept actions such as loading a plugin or fetching content from the internet. The platform cross-checks each tool or add-on against a maintained whitelist and applies enforcement rules when components are unknown or flagged. A central claim is that continuous re-verification is necessary because previously safe components can become dangerous if their dependencies or distribution channels change.



To build and sustain that whitelist, AIR continuously evaluates publicly available skills and add-ons for changes and malicious indicators. The company observes that a nontrivial share of components discovered online are problematic; AIR reports filtering roughly 27% of add-ons and skills it finds. This percentage illustrates the dynamic risk model: third-party packages, developer account compromises, or altered downloads can convert an innocuous plugin into a threat.



The recent funding consisted of two seed rounds closed within weeks of each other: $10 million led by Sequoia and $40 million led by Greenoaks, with participation from angel investors and industry figures. The new capital is directed mainly toward hiring researchers and expanding go-to-market operations in the U.S. and Europe. AIR states it already serves more than 20 customers, about a quarter of which are large enterprises, with particular traction in regulated sectors such as financial services and pharmaceuticals.



While AIR positions continuous vetting as its competitive differentiator, it operates in a crowded market. Other vendors offer overlapping capabilities: discovery and runtime protections for agents and MCP servers, governance and security tooling, identity and access controls for agent processes, and gateways to mediate agent traffic. Significant venture funding has flowed into related companies, demonstrating market belief in the category’s importance and scale.



AIR’s leadership contends the company’s moat stems from the difficulty of continuously vetting the broad ecosystem of skills and plugin sites in real time. Visibility at endpoints, they argue, is easier to achieve and will be broadly implemented; the long-term infrastructure challenge is maintaining near-real-time verification and re-verification across an entire fleet of agents and their dependencies. Investors supporting the company emphasize that the problem is as much infrastructure and pipeline engineering as it is traditional security scanning: re-inspecting each component every time it changes across many agents is an operationally heavyweight task.



Looking ahead, AIR and similar providers expect AI platform vendors to introduce native security checks and policy controls. However, enterprises—particularly those operating across multiple vendor ecosystems or requiring vendor-agnostic governance—are likely to want independent solutions that provide consistent controls and continuous verification across all agents and add-ons they permit. The practical outcome is a market where native platform protections exist alongside third-party oversight tools that provide cross-vendor telemetry, enforcement, and compliance reporting.



Key Insights Table































Aspect Description
Market Need AI agents expand attack surfaces via skills, plugins, and add-ons, creating a need for discovery and continuous vetting.
Product Approach Visibility to find agents, enforcement hooks to intercept actions, and a continuously updated whitelist of vetted components.
Funding Raised $50M in two seed rounds led by Sequoia and Greenoaks to expand research and market presence.
Customers More than 20 customers, with significant traction in regulated industries like finance and pharmaceuticals.
Competitive Landscape Several companies offer discovery, governance, and runtime protections; differentiation centers on continuous re-verification and cross-vendor coverage.


Afterwards...


As enterprises integrate AI agents more deeply, future efforts should prioritize standardized metadata and signing practices for skills and plugins, increased transparency around component provenance, and vendor-neutral verification infrastructure. Investing in research on automated behavioral analysis and rapid re-verification pipelines will help address the dynamic risk posed by evolving third-party components. Additionally, cross-industry collaboration to define security and compliance standards for agent ecosystems could reduce fragmentation and make continuous vetting more scalable. Emphasizing these approaches will support safer, more auditable agent deployments while preserving the productivity benefits AI agents can deliver.



Continued exploration of runtime observability, provenance metadata standards, and automated remediation workflows will be essential to manage the growing supply chain of AI agent components.


Last edited at:2026/9/1

數字匠人

Idle Passerby