Product1 distinct publisher3 min readPublished
The company's researchers count 17,800 public add-ons pulling unverified instructions, a number produced by the same firm selling the fix, which still leaves operators with an inventory problem they own either way.
The Product Desk · Product desk

Compiled by The Product DeskSomething wrong?How this is made
A developer asks a coding agent to fix a failing test at four in the afternoon, and the agent decides it needs a tool it does not have. It finds one, loads it, and finishes the job. No ticket was filed, because no human made a decision anyone thought worth recording. Greenoaks partner Patrick Backhouse, whose firm led AIR's larger round, put that sequence in procurement language: agents work at runtime with skills, plugins, add-ons and MCP servers "from sources that no security team has reviewed" [8].
Teams tell themselves that add-ons get reviewed, so the inventory is known. The mechanism does not actually support that assumption. AIR's platform maps the agents already running across endpoints, cloud accounts and SaaS apps and then keeps re-checking their components, on the reasoning that a skill which passed review in March can be rewritten in June by whoever maintains it [3]. Sequoia's Bogomil Balkansky told TechCrunch this is "not a scanning problem" but one of continuous re-verification [9]. Set aside the vendor framing and the point stands on its own: an approval stamped on a mutable artifact expires quietly, and nothing in your pipeline tells you when.
The numbers are worth working through directly. AIR's researchers say more than 17,800 public add-ons, accounting for 6.7 million installations, drew instructions from outside sources nobody had verified [4]. That averages about 376 installations per add-on [1]. A handful of popular components will be pulling that average upward, so treat it as a shape rather than a typical case, and the shape is not a long tail of hobby projects with two users each.
Now the caveat that has to travel with the number. The 17,800 count and the claim that roughly 27% of the add-ons and skills AIR finds online get filtered out [6] both come from the company's own research team, and AIR also operates a marketplace of add-ons it has already cleared [10]. The figures are not necessarily wrong for that reason, but the denominator behind them cannot be independently checked, and 27% describes what AIR's crawler encountered, not what the agents in your estate actually reach for on a Tuesday. The impersonation finding is the harder one to argue with: skills posing as Anthropic and OpenAI that could run arbitrary code once installed [5], which puts the trust decision in the hands of whoever typed the title.
The buyer list tells you who this is for today. More than 20 companies use the platform, about a quarter of them large enterprises, with demand strongest in financial services and pharmaceuticals, according to TechCrunch [7]. A quarter of twenty is roughly five large enterprises [2]. AIR also hired Ryan Knisley, formerly CISO at Disney and Costco, as chief strategy officer [14]. Regulated industries where a named human signs an attestation are buying first, which is what you would expect.
The sorting question costs nothing: for every component your agents can reach, who chose it, and who can change it after you said yes. Human-chosen and pinned is ordinary dependency management. Human-chosen and maintainer-editable is the package-registry problem, with a decade of known answers. Agent-chosen and pinned barely exists, because agents resolve tools by name at runtime. Agent-chosen and maintainer-editable is the box AIR is selling into, and you can populate it this week for free by listing the MCP servers and skill sources any agent in your estate can reach, with a human name beside each one who can push a change. If that list is short, an inline proxy sitting on every agent call is a new dependency and a new outage you do not need. If you cannot produce the list at all, buying the firewall gets you the list, which may be most of what you are paying for.
Ranked by verification strength, evidence, and original report placement.
AIR Security Inc. formally launched with $50 million in funding to build what it calls an inline firewall for AI agents.
AIR is based in New York and will spend the new money on hiring researchers and building out sales in the U.S. and Europe.
AIR's software sits in the path between agents and their components, screening the instructions, tools and data heading into an agent's context before the agent acts on any of it.
AIR's platform maps the agents already running across endpoints, cloud accounts and SaaS applications, then keeps re-checking the components those agents depend on, because a skill that passed review in March can be rewritten in June by whoever maintains it.
AIR company researchers found that more than 17,800 public AI add-ons, accounting for 6.7 million installations, drew instructions from outside sources nobody had verified.
AIR's team found AI skills impersonating Anthropic PBC and OpenAI Group PBC that could run arbitrary code once installed.
Distinct publishers with included, body-backed reporting in this cluster.
2 articles · September 1, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
invest
AIR Security banks $50 million six months in on a census of 17,800 untrusted AI add-ons1 distinct publisher
build
AIR Security raised $50M to inspect the skills an agent loads before it loads them1 distinct publisher
build
Anthropic's $1.5B Ode bets model value sits with embedded engineers, not API keys1 distinct publisher
product
A 2x LLM bill is not a bug report: token spend is an observability problem1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One outlet, filed twice
Strip out the duplicate and this story has a single witness: SiliconANGLE, working from AIR's launch announcement. The mechanism claims are coherent and specific, which is worth something. The numbers are not independently anything — 17,800 add-ons and a 27% rejection rate come from the vendor's own scan with no published method, and the customer figures are relayed from TechCrunch, an outlet that never appears in our sources. Nobody outside the deal has checked a single digit.
Two dozen logos, none named
Real but early. More than 20 customers and about five large enterprises is a genuine commercial signal for a company six months old, and the sector concentration in banks and pharma is plausible for a control that maps unreviewed dependencies. It is also the floor of what a launch discloses: no named account, no revenue, no deployment scale, and the count reaches us secondhand. Forty employees and a marketplace of pre-cleared add-ons suggest the product exists; nothing here shows it running at scale in anyone's production estate.
The firewall analogy outruns the proof
"Every enterprise has a firewall protecting its network. Now they need one protecting their AI agents" is a category claim, and category claims need more than five enterprise accounts and a self-run scan behind them. The gap is not that the underlying risk is fake — unreviewed skills that mutate after approval is a legitimate control problem, and the impersonation finding lands. The gap is between a stated market-wide necessity and evidence that consists of one vendor's count of its own crawl plus a customer number borrowed from another outlet.
The threat count and the fix share an author
Follow the voices: the company, its Series A lead, its Series B lead. AIR counted the danger, AIR sells the screen, and AIR also decides which add-ons make it into the cleared marketplace — a gatekeeper position with obvious commercial upside and no disclosed appeals process. Balkansky's "not a scanning problem" line does double duty as product positioning and mark defence for a $10 million entry now sitting behind a $40 million round. None of that makes the finding wrong; it does mean every number in this story was produced by someone who profits if you believe it.
Fine to note, too thin to act on
High confidence in the plumbing facts — who founded it, who funded it, what the product claims to do — because those are checkable and consistently stated. Low confidence in anything a decision would rest on: the exposure numbers, the rejection rate, the customer trajectory. A second outlet, a named deployment, or a method behind the 17,800 would move this fast in either direction.