The Growing Security Challenge of AI Agent Tooling
As businesses integrate AI agents into their daily operations, a parallel software supply chain has quietly taken shape around the tools these agents depend on. From skills and plugins to MCP servers and add-ons, these components give agents their ability to interact with the internet and enterprise systems — but they also introduce a new attack surface that most organizations are not yet equipped to manage.
The risk is distinct from traditional cybersecurity threats. Rather than attacking a system directly, adversaries can poison the content an AI agent consumes, or tamper with a skill or plugin after it has been approved. Because these tools often load executable code into agent environments, a single compromised add-on can cascade across an entire enterprise deployment.
How AIR’s Platform Works
AIR offers a platform built around three layers of defense. First, a visibility engine discovers AI agents active across a company’s environment, including those deployed by employees outside of official IT approval or using personal accounts. Second, an enforcement layer hooks into running agents to intercept and analyze actions in real time — such as loading a skill or fetching content from an external source. Third, a whitelist-based filtering system checks every tool, add-on, or plugin an agent intends to use against a continuously updated list maintained by the startup.
The company says it currently filters out roughly 27% of the add-ons and skills it finds online, removing those that exhibit malicious behavior or have been altered since their initial approval. Because a previously safe skill can become risky if its underlying package changes or its developer’s account is compromised, the startup argues that one-time verification is insufficient.
The Funding Behind the Push
Founded by Yair Saban and Niv Hoffman — both veterans of Israel’s Unit 8200 intelligence corps, where they worked on offensive cybersecurity — AIR closed two seed rounds within weeks of each other. The first round raised $10 million, led by a major Silicon Valley venture firm. The second brought in $40 million, led by a different prominent investor. Several angel investors from the cybersecurity and enterprise software sectors also participated.
The startup currently employs around 40 people and claims more than 20 customers, roughly a quarter of which are large enterprises. Demand has been strongest in heavily regulated industries, particularly financial services and pharmaceuticals. The new capital will primarily fund research hiring and expansion of go-to-market operations in the United States and Europe.
A Crowded but Expanding Market
AIR is entering a space that has already attracted significant venture capital. Several competitors offer overlapping capabilities, ranging from agent discovery and access controls to runtime monitoring and MCP gateways. One rival recently closed a $125 million Series C round, while another raised $100 million in a Series B. The influx of investment signals that the market sees real urgency in securing AI agent ecosystems before they become systemic risks.
Why Continuous Verification Matters
The core argument for AIR’s approach is that securing AI agent tools is not a one-time scan but an ongoing process. Saban draws a parallel to the evolution of driver security in operating systems: in the early 2000s, drivers did not require digital signatures. Today, every driver installation displays a signature verifying its publisher — because drivers load code directly into the kernel. AI agent skills and plugins operate on the same principle, yet they remain largely unsigned and unverified.
While AI labs and providers may eventually build filtering mechanisms into their own platforms, the startup believes enterprises will still want an independent product that works across multiple vendors and agent frameworks. As one investor at a lead funding round put it, inspecting every skill, plugin, and sub-agent an enterprise’s agents touch — re-inspecting each one every time it changes, in real time and across an entire fleet — is an infrastructure problem long before it is a security problem.






