Key Takeaways
- AIR left stealth on September 1, 2026 with $50 million across two seed rounds — $10 million led by Sequoia, $40 million led by Greenoaks — TechCrunch reported.
- CEO Yair Saban told TechCrunch that AIR's platform currently filters out about 27% of the add-ons and skills it finds online.
- AIR's own research found more than 17,800 public AI add-ons, representing 6.7 million installations, that relied on untrusted external instruction sources, Dealroom reported.
- AIR says it has more than 20 customers and around 40 employees, with the strongest demand in financial services and pharmaceuticals.
An Israeli security startup called AIR left stealth on September 1 with $50 million and a specific claim: most companies cannot say which skills, plugins and MCP servers their AI agents have installed. TechCrunch reported the money came as two seed rounds closing within weeks of each other — $10 million led by Sequoia, then $40 million led by Greenoaks. The bet: agent tooling has become a software supply chain running without the review ordinary software earned two decades ago.
The supply chain nobody drew on the architecture diagram
As companies hand agents access to more of their systems, TechCrunch writes, “a nascent software supply chain seems to be forming around the new tooling AI agents are using: skills, plug-ins, MCP servers, and add-ons that let them interact with the internet.” Those components get installed casually, sometimes by the agent itself, carrying instructions and code into a process that already holds credentials.
Saban, who co-founded AIR with CTO Niv Hoffman, argues the point through device drivers. “Today, every time you install a driver, you see a signature saying who signed it, because the driver is actually loading code into the kernel,” he told TechCrunch. Skills, plug-ins and MCPs get no such signature, he said — the same mechanism, the same lesson, not learned.
Both founders are veterans of Israel’s Unit 8200 intelligence corps, where TechCrunch reports they worked on offensive cybersecurity. The risk Saban emphasizes is not an attacker hitting the agent head-on, but poisoning what it consumes — the pages and content it fetches — so the agent does the damage.
What AIR says the product actually does
Per TechCrunch, the platform has three parts. Discovery finds agents running inside a company’s environment and flags employees using AI tools IT never approved, or personal accounts for work. An enforcement layer hooks into agents to intercept and analyze actions — loading a skill, fetching content from the internet — as they happen. Every tool is then checked against a whitelist AIR maintains.
Dealroom adds a detail that matters: when a component turns out to be malicious, vulnerable or unapproved, teams can trace every workflow depending on it and revoke it. Without that reverse index you know you have a problem but not what breaks when you fix it. AIR also runs a marketplace of pre-vetted add-ons.
The whitelist is what AIR treats as the hard part. Saban told TechCrunch it is maintained by continuously evaluating publicly available skills for changes and malicious behavior, because an approved skill can go bad later — a package it downloads changes, or its developer’s account is compromised. Endpoint visibility, he argued, is the easy half that everyone will build; continuous vetting is where he thinks the moat is.
The numbers AIR is using to sell the problem
AIR’s own research is the announcement’s most concrete part. Dealroom and cryptobriefing report the same two findings: AIR says it identified more than 17,800 public AI add-ons — roughly 6.7 million installations — that relied on untrusted external instruction sources, and it found AI skills impersonating brands including Anthropic and OpenAI to slip past platform reviews and run arbitrary code.
Then the operational number: Saban told TechCrunch the platform currently filters out about 27% of the add-ons and skills it finds online. Read that as a vendor’s own pass/fail rate, not an industry statistic — no independent audit appears in any of the three reports, and the company selling the filter is grading the ecosystem.
Ungoverned skills do not stay neutral either; they turn into governance debt someone eventually has to pay down.
Who wrote the checks, and who else is chasing this
TechCrunch reports Sequoia led the first round and Greenoaks the second; Dealroom describes the same $50 million as a single seed co-led by both firms, so the structure is reported differently by outlet. Swish, Netz and angels including Yinon Costica (co-founder of Wiz) and Varun Anand (co-founder of Clay) also joined.
“This is not a scanning problem, it is a continuous re-verification problem,” Sequoia partner Bogomil Balkansky told TechCrunch. Re-inspecting every skill, plugin, MCP server and sub-agent each time it changes, he argued, “is an infrastructure problem long before it is a security problem.” Greenoaks partner Patrick Backhouse, quoted in Dealroom’s write-up, said agents use “skills, plugins, add-ons, and MCPs from sources that no security team has reviewed.”
At $50 million, Dealroom notes, the round ranks in the top 1% of 937 comparable US security seed rounds over the trailing 48 months. AIR also hired Ryan Knisley, former chief information security officer at The Walt Disney Company and Costco Wholesale, as chief strategy officer.
The category is crowded and well funded. TechCrunch lists Noma Security, Zenity, Astrix Security and Operant AI as rivals doing overlapping discovery, access control and runtime monitoring, and notes Zenity raised a $125 million Series C in August and Noma a $100 million Series B last year. AIR has around 40 employees; the new capital goes mainly to researchers and go-to-market in the U.S. and Europe, Saban said.
What to do this week, whether or not you buy anything
Four moves follow from the failure modes in these reports. None require a purchase order.
Inventory the agents first, including the ones IT never approved. AIR’s discovery layer exists because companies do not know what is running — in most organizations, Saban said in comments quoted by Dealroom, “nobody knows what’s running, what’s trusted, or how to shut it off.” Yours is a list of every agent, every skill or MCP server it loads, and which arrived via a personal account.
Treat approval as expiring. The decay Saban describes — a downloaded package changes, a developer’s account is compromised — means the skill you reviewed in July is not necessarily the one running today. Re-check on change, not on a calendar.
Verify the publisher, not the name. AIR says it found skills impersonating Anthropic and OpenAI to get past platform review, so a familiar brand string is not provenance. That is worth weighing when you decide whether an agent gets a tool through MCP or a plain CLI, because the two paths give very different visibility into what actually ran.
Assume fetched content is hostile input. The poisoning path AIR describes targets what enters the agent’s context, not its code. Scope credentials to the task, and do not treat a permissive execution mode as a boundary — as the Claude Code auto-mode bypass showed, a mode that is not a sandbox will not save you.
What happens next
The obvious threat to AIR’s business is that the model providers absorb it. Saban acknowledged to TechCrunch that AI labs will eventually build in checks against malicious skill and tool usage, but argued companies will still want a product that works across vendors. Watch whether platform-native signing arrives before independent vetting becomes a habit.
Two other things are worth tracking: whether the 27% rejection rate holds up when anyone outside AIR measures it, and whether 20-plus customers can defend a top-1% seed round against rivals who already raised nine figures.
Quick poll
Does your team know which skills and MCP servers its agents have installed?
Saban told TechCrunch that AIR's platform currently filters out about 27% of the add-ons and skills it finds online.
FAQ
What does AIR actually sell? Per TechCrunch, a platform that discovers AI agents inside a company, continuously vets the skills and components they use, and blocks them from software or external sources that fail its security criteria. It also runs a marketplace of vetted add-ons.
How much did AIR raise, and who led it? $50 million total. TechCrunch reports two seed rounds closing within weeks of each other, $10 million led by Sequoia and $40 million led by Greenoaks; Dealroom describes it as a single seed co-led by the two firms.
Why are agent skills and plugins a security problem? They load code and instructions into a process that already has access to company systems, and unlike device drivers they are not signed. AIR says it found skills impersonating Anthropic and OpenAI to bypass platform reviews and run arbitrary code.
Is AIR the only company doing this? No. TechCrunch names Noma Security, Zenity, Astrix Security and Operant AI as competitors; Zenity raised a $125 million Series C in August and Noma a $100 million Series B last year.