Build1 distinct publisher3 min readPublished
The founders' claim is that permissions describe an agent's reach while its context decides its behaviour, and their own scan of 142,836 public skills flagged roughly one in eight as leaning on an external resource they could not vouch for.
The Engineer · Build desk

Compiled by The EngineerSomething wrong?How this is made
Saban told Ctech that every enterprise has a firewall protecting its network and now needs one protecting its AI agents [20]. Take that analogy literally, because the company does: a firewall is a policy decision point sitting in the request path, and AIR Security says it sits inline, evaluates external content and components, and can stop an agent from loading a skill, visiting a source or invoking a tool that fails its checks [5]. Where that check actually runs, the material does not say. An MCP gateway, an egress proxy and a client-side wrapper all satisfy the description, and they differ on failure behaviour and on whether they see a sub-agent that fetches its own instructions from the internet [19].
The reason there is room for a product here is written into the protocol. The Model Context Protocol specification tells clients to treat tool annotations as untrusted unless they come from trusted servers, to validate results before passing them to a model, and to keep humans able to deny sensitive actions [6]. That is an assignment of work, not a mechanism. The spec conditions trust on the server being trusted and leaves establishing that to whoever deploys the client, and nothing in that instruction covers a server that was fine last month. Which is the gap the continuous-evaluation pitch aims at: a clean plug-in turns dangerous when a developer account is compromised, a referenced package changes, or an expired domain is bought by somebody else, and a one-time scan cannot catch it [7].
The research number deserves the treatment any vendor benchmark gets. Divide the flagged count by the scanned count and you get 12.48%, which rounds to 12.5%, not the published 12.4% [1]. For a research team generating demand, rounding down is at least the polite direction. The 6.7 million installations attributed to the flagged set [9] work out to about 376 installs per skill on average [2], so the flagged population is mostly long tail unless a few popular skills carry the mass, and the study as described does not break that out. The trust scores come from signals like young domains, lightly used GitHub accounts, look-alike brands, new packages and abandoned hosting [10], and AIR itself says those indicators describe exposure rather than confirmed malicious activity, and that the figures are company-generated and not independently validated [11]. For the percentage to transfer to your fleet, your agents would have to be pulling from that same public marketplace population, and you would have to accept domain age and account activity as proxies for risk in an inventory you curated yourself.
The spend tells you who the buyer is. Roughly 40 people [13], with money earmarked for security researchers and commercial expansion in the US and Europe [18], and a former Walt Disney and Costco CISO installed as chief strategy officer [14]. The follow-on came in at four times the first round [3]. The same company is also building a marketplace where organisations can distribute pre-vetted add-ons [16], which puts the party scoring components in the business of shipping them, and the material does not say how those two functions are kept apart.
Ranked by verification strength, evidence, and original report placement.
Yair Saban and Niv Hoffman met in the Israeli military about a decade ago and later worked in offensive cybersecurity, enterprise infrastructure and AI security research.
AIR Security came out of stealth on September 1st with $50 million raised across two seed rounds; the company was founded in February 2026 by Yair Saban and Niv Hoffman.
Sequoia Capital led an initial $10 million seed round, and Greenoaks led a $40 million follow-on that closed within weeks, according to TechCrunch; Swish Ventures and Netz also participated.
AIR Security was founded around the view that permissions tell security teams what an agent can reach, while the information entering its context can determine what it actually does.
AIR Security sits inline, evaluates external content and components, and can stop an agent from loading a skill, visiting a source or invoking a tool that fails its checks.
The MCP specification tells clients to treat tool annotations as untrusted unless they come from trusted servers, validate results before passing them to a model, and keep humans able to deny sensitive actions.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 1, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
invest
AIR Security banks $50 million six months in on a census of 17,800 untrusted AI add-ons1 distinct publisher
build
The $559M-versus-$12.3B quarter matters more than the $65B run rate4 distinct publishers
security
Air Security hijacked live Official MCP Registry entries by buying their expired domains1 distinct publisher
build
AWS wires Bedrock Guardrails into the hook that fires before a Strands agent calls a tool1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One outlet, two attributions, zero outside verification
The verifiable spine here is thin but solid: a launch date, a two-part round with named leads, headcount, an executive hire. Runtimewire sources the Greenoaks tranche to TechCrunch and the founder interview to Ctech, so the money facts have somewhere to land. Everything that makes the story interesting — the scanned corpus, the flagged share, the 26,000 agents reached by a planted skill — comes from the vendor's own research shop, and the reporting says outright that it has not been independently validated. Even the published percentage doesn't quite match its own arithmetic: 17,822 of 142,836 is 12.48%, not 12.4%.
Twenty-odd unnamed customers, six months in
What exists is a company six months old with roughly 40 people, more than 20 customers it will not name, and a claimed concentration in financial services and pharma. That is a real start and nothing like proof of a category. The 6.7 million installations behind flagged skills describe the size of the exposed surface, not anyone's use of this product — a distinction easy to lose when both numbers sit in the same paragraph. The marketplace for pre-vetted add-ons is still an intention.
Exposure counted, then spoken of as risk
'One in eight skills untrusted' does a lot of rhetorical work for a measurement that only says a skill points at a young domain or a thin GitHub account. None of those 17,822 skills is shown to have done anything. The planted-skill experiment is the strongest evidence in the story and it is also a demo the company designed and disclosed itself. Runtimewire deserves credit for labelling the gap rather than widening it — the overstatement lives in the framing the research was built to produce, not in the write-up.
The research is the funnel, and it says so
This is about as legible as incentives get. The company that scanned the skills sells the scanner; the reporting states plainly that the research operation exists to demonstrate the problem and generate demand. Investors who just put $50 million in have every reason for the exposure number to be large, and the pitch's own logic — get a control point in place before the model providers bundle one — rewards urgency over precision. Worth noting the angel list runs through Wiz, Cognition and Clay, people whose reputations attach to the category taking off.
Confident about the cheques, cautious about the threat
Split the story and the confidence splits with it. Who funded what, when, and who was hired — settled, and cross-attributed. Whether one in eight agent skills constitutes a live danger, and whether an inline filter is the answer — resting on one publisher relaying one company's numbers, with no competitor, customer or outside researcher to test them. Six months of company history is also not much of a track record to reason from.