AI Security AI安全 4h ago Updated 2h ago 更新于 2小时前 48

AI Agent Firewall Startup AIR Security Emerges From Stealth With $50 Million AI Agent 防火墙初创公司 AIR Security 以 5000 万美元融资秘密亮相

AIR Security emerged from stealth with $50 million in funding led by Sequoia Capital and Greenoaks to build an AI-specific firewall for securing AI agents Research revealed over 17,800 public AI add-ons with 6.7 million installations relying on untrusted external instruction sources, including impersonated skills mimicking Anthropic and OpenAI The AIR firewall continuously evaluates every skill, plugin, MCP server, and add-on across the AI agent supply chain, screening for external instructions, AIR Security完成5000万美元融资,推出专为AI agents设计的防火墙AIR 研究发现超17,800个公共AI add-ons(670万安装量)依赖不受信任的外部指令源 发现伪装成Anthropic/OpenAI的恶意AI Skills,可绕过安全审查执行任意代码 企业正加速采用Claude Code、Cursor等编码agent工具,但缺乏安全防护机制 AIR提供持续评估、供应链追踪和预认证add-on市场,构建AI agent安全生态

72
Hot 热度
65
Quality 质量
70
Impact 影响力

Analysis 深度分析

TL;DR

  • AIR Security emerged from stealth with $50 million in funding led by Sequoia Capital and Greenoaks to build an AI-specific firewall for securing AI agents
  • Research revealed over 17,800 public AI add-ons with 6.7 million installations relying on untrusted external instruction sources, including impersonated skills mimicking Anthropic and OpenAI
  • The AIR firewall continuously evaluates every skill, plugin, MCP server, and add-on across the AI agent supply chain, screening for external instructions, hidden behaviors, and typo-squatted packages
  • The solution provides pre-deployment analysis and post-deployment monitoring, with the ability to trace and revoke compromised add-ons across the organization in real time
  • AIR also operates a marketplace of pre-vetted, certified add-ons to give enterprises a safe route for expanding agent capabilities without introducing unmanaged risk

Why It Matters

As AI agents become foundational to enterprise operations—particularly coding agents like Claude Code, Cursor, and Codex—organizations are adopting them rapidly without adequate security controls. AIR Security addresses a critical gap: while enterprises have firewalls protecting their networks, there is no equivalent protection for what enters an agent's context, leaving them vulnerable to prompt injection, supply chain attacks, and unauthorized actions.

Technical Details

  • AIR Security's firewall discovers and evaluates every skill, plugin, MCP server, and add-on across an organization's AI agent supply chain, performing deep analysis against known agentic attack patterns before and after deployment
  • The system screens for external instruction sources, hidden behaviors, typo-squatted packages masquerading as official developer tools, and vulnerable supply chains
  • Continuous monitoring automatically revokes trust if a maintainer pushes a malicious update or an existing integration is compromised, with the ability to trace every agent and workflow depending on a given add-on
  • The company's research identified AI Skills impersonating major companies like Anthropic and OpenAI designed to bypass security reviews and execute arbitrary code
  • AIR offers a marketplace of pre-vetted, certified add-ons built from continuous evaluation of agentic activity across multiple customers

Industry Insight

  • The AI agent security market is emerging as a critical infrastructure layer; enterprises adopting agentic tools like Claude Code and Cursor will need solutions like AIR to deploy with confidence, creating a significant commercial opportunity
  • Supply chain security for AI add-ons will become a top priority for CISOs, paralleling the evolution of traditional software supply chain defenses like SBOMs and package signing
  • The analogy of AI agents as the new operating system and add-ons as applications suggests that future security frameworks will need to treat agent context boundaries with the same rigor as network perimeters, likely driving regulatory and compliance requirements in the near term

TL;DR

  • AIR Security完成5000万美元融资,推出专为AI agents设计的防火墙AIR
  • 研究发现超17,800个公共AI add-ons(670万安装量)依赖不受信任的外部指令源
  • 发现伪装成Anthropic/OpenAI的恶意AI Skills,可绕过安全审查执行任意代码
  • 企业正加速采用Claude Code、Cursor等编码agent工具,但缺乏安全防护机制
  • AIR提供持续评估、供应链追踪和预认证add-on市场,构建AI agent安全生态

为什么值得看

AIR Security揭示了AI agent生态中日益严峻的安全隐患,为正在快速采用AI agent的企业提供了关键的安全基础设施方案。随着AI agent成为企业核心生产力工具,其供应链安全风险已成为行业亟待解决的战略性问题。

技术解析

  • AIR防火墙架构:在部署前后对组织AI agent供应链中的技能、插件、MCP服务器和add-on进行全面发现和评估,检测外部指令源、隐藏行为和typo-squatting包
  • 持续监控机制:一旦检测到恶意更新或集成被攻破,自动撤销信任并追踪所有依赖该add-on的agent和工作流
  • 预认证add-on市场:通过跨客户持续评估agentic活动,提供经过验证的认证add-on,降低引入未管理风险的可能性
  • 攻击模式分析:基于已知agentic攻击模式进行深度分析,筛查伪装成官方开发者工具的恶意包

行业启示

  • AI agent安全将成为企业AI部署的关键门槛,防火墙类基础设施需求将快速增长
  • 企业需建立AI agent供应链治理框架,对第三方add-on实施持续监控和准入机制
  • AI agent安全市场正处于早期阶段,AIR的融资信号表明资本看好这一细分赛道的发展潜力

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Agent Agent Security 安全 Funding 融资