Security1 distinct publisher3 min readPublished
The census behind a Sequoia-led round describes 6.7 million installations of add-ons that fetch their instructions at runtime, some of them Skills impersonating Anthropic and OpenAI to clear a security review.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
An add-on that pulls its instructions from somewhere else carries a pointer through review, not its payload. The fetch happens at runtime, the retrieved text lands in the agent's context, and the agent treats it the way it treats a user's prompt. Nothing inside the installed package has to change for its behaviour to change, which is why a one-time install check does not cover it.
AIR Security puts the number of public AI add-ons doing this at more than 17,800, across 6.7 million installations [2]. Divide one by the other and the average affected add-on sits on roughly 376 installs [11]. The distribution is not published, so the mean is the only shape available, but it is not the shape of abandoned junk with two users each.
The impersonation finding is the part that generalises. AIR says it found Skills in the wild posing as Anthropic and OpenAI, written to get past security review and then execute arbitrary code [3]. Its own screening list includes typo-squatted packages masquerading as official developer tools [6], and it is the same failure one register up, trust assigned by name string in ecosystems with no publisher verification worth the name.
All of it is the vendor's own research, and the launch account gives no method, no scan window and no list of the registries enumerated [14]. So treat the counts as an order of magnitude asserted by the company selling the fix. The fix, as described, discovers and evaluates every skill, plugin, MCP server and add-on before and after deployment [5], propagates revocation to every dependent agent and workflow [7], and offers a marketplace of pre-vetted add-ons [8]. That is a product description, with no deployment data attached to it yet.
What holds regardless is the inventory gap that CEO Yair Saban names in the launch: agents are autonomously installing tools and connecting to internal systems, and in most organisations nobody knows what is running, what is trusted, or how to shut it off [4]. AIR points at coding agents specifically, naming Claude Code, Cursor and Codex as where the volume is coming from [10]. Those tools install their extensions on developer machines, at developer pace, which is where the enumeration work sits.
An agent that reads files and email, holds credentials to internal systems and acts on behalf of an employee [13] is a privileged process, and third-party instructions reaching its context are an input path with no gate. A team that can list its installed Skills and MCP servers per host, and mark which of them fetch text from a URL at runtime, has priced this problem without a purchase order; a team that cannot has an unbounded number of extensions holding production credentials, whatever the size of the round.
Ranked by verification strength, evidence, and original report placement.
AIR Security emerged from stealth with $50 million in funding led by Sequoia Capital and Greenoaks, together with a range of prominent individual industry angels, and a firewall product also called AIR built for AI agents.
AIR co-founder and CEO Yair Saban says agents are autonomously installing tools, connecting to internal systems and making decisions, and that in most organizations nobody knows what is running, what is trusted, or how to shut it off.
The source describes AI agents connecting to more tools, data and third-party services, browsing websites, accessing files and emails and acting on behalf of employees, with adversary influence via poisoned content or direct compromise opening a path to data theft, fraud or unauthorized access while giving security teams little visibility.
The 17,800 add-ons and 6.7 million installations work out to an average of about 376 installations per affected add-on.
The launch account reports the 17,800 add-on and 6.7 million installation figures without stating a method, a scan window, or which registries were enumerated, and the research is the vendor's own.
AIR Security research found more than 17,800 public AI add-ons, representing 6.7 million installations, relying on untrusted external instruction sources.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 3, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
product
AIR Security raises $50M to screen the unverified plugins AI agents pull in at runtime1 distinct publisher
security
Uber ships ADR, and hands agent-security vendors a number to be measured against1 distinct publisher
invest
AIR Security banks $50 million six months in on a census of 17,800 untrusted AI add-ons2 distinct publishers
product
A 2x LLM bill is not a bug report: token spend is an observability problem1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One outlet, one interested source
Strip out AIR Security's announcement and this story has nothing left. SecurityWeek relays the count, the impersonating Skills and the firewall's behavior without a second voice, and the research that gives the piece its news value names no registry and no scan date. The threat model around it is well established; the specific measurements are not checkable by anyone reading.
A launch, plus customers referred to only in the plural
What actually exists in public is a funding announcement and a product description. The only hint of usage is the marketplace's dependence on 'continuous evaluation of agentic activity across many customers' — a phrase doing a lot of work for a company just leaving stealth, with no name, count, or sector attached. The 6.7 million installations are other people's add-ons, not AIR's footprint.
Category framing well ahead of the receipts
Agents as the new operating system, add-ons as the new applications, a firewall for what enters an agent's context, enterprises wanting a seatbelt — the vocabulary arrives fully formed and unchallenged. The overreach is quieter than the slogans, though: 6.7 million installations of add-ons that fetch external instructions is a description of how the ecosystem is built, not evidence of 6.7 million compromises, and the story lets the number carry alarm it hasn't earned. Meanwhile the genuinely sharp finding, Skills wearing Anthropic's and OpenAI's names to clear review, gets one sentence and no follow-up.
The research is the pitch
The census and the product launch are the same announcement: the number that establishes the problem was produced by the company selling the fix, timed to a $50 million raise, and the marketplace turns its verdicts on third-party add-ons into a commercial gatekeeping position. Sequoia and Greenoaks have a stake in the category reading as urgent. None of this makes the finding wrong; it does mean nobody in this story had a reason to check it.
Confident about the shape, not the size
That agent add-ons pulling instructions at runtime are a real and poorly governed attack surface, we can say with some assurance — it matches everything else in this space. That there are precisely 17,800 of them across 6.7 million installations, or that AIR's firewall does what its description says, rests on a single interested account and cannot be firmed up from what we have.