Summary
On September 1, 2026, AIR (Air Security) launched from stealth with $50 million in seed funding, led by Sequoia and Greenoaks, to build an inline firewall for AI agents. AIR continuously discovers and evaluates every skill, plugin, MCP server, and add-on across an organization's agent supply chain before and after deployment, and lets security teams trace and revoke any that are malicious, vulnerable, or unapproved.
What changed
AIR came out of stealth with $50M in seed funding to ship a firewall that inventories and continuously reinspects agent add-ons, plugins, and MCP servers, flagging untrusted ones; it reported that more than 17,800 public AI add-ons, spanning 6.7 million installations, relied on untrusted external instruction sources.
Why it matters
As agents pull in third-party skills, plugins, and MCP servers, the agent supply chain becomes a new attack surface with little visibility or control. Dedicated discovery-plus-revocation tooling reflects rising enterprise demand for governance over what agents can install and call, and signals investor conviction that agent security is a distinct category.
Evidence excerpt
AIR continuously discovers and evaluates every skill, plugin, MCP server, and add-on across an organisation's AI agent supply chain, before and after deployment... AIR found that more than 17,800 public AI add-ons - representing 6.7 million installations - relied on untrusted external instruction sources.