AI Agent Firewall Startup AIR Security Emerges From Stealth With $50 Million
AIR Security emerged from stealth with $50 million in funding led by Sequoia Capital and Greenoaks to build an AI-specific firewall for securing AI agents Research revealed over 17,800 public AI add-ons with 6.7 million installations relying on untrusted external instruction sources, including impersonated skills mimicking Anthropic and OpenAI The AIR firewall continuously evaluates every skill, plugin, MCP server, and add-on across the AI agent supply chain, screening for external instructions,
Analysis
TL;DR
- AIR Security emerged from stealth with $50 million in funding led by Sequoia Capital and Greenoaks to build an AI-specific firewall for securing AI agents
- Research revealed over 17,800 public AI add-ons with 6.7 million installations relying on untrusted external instruction sources, including impersonated skills mimicking Anthropic and OpenAI
- The AIR firewall continuously evaluates every skill, plugin, MCP server, and add-on across the AI agent supply chain, screening for external instructions, hidden behaviors, and typo-squatted packages
- The solution provides pre-deployment analysis and post-deployment monitoring, with the ability to trace and revoke compromised add-ons across the organization in real time
- AIR also operates a marketplace of pre-vetted, certified add-ons to give enterprises a safe route for expanding agent capabilities without introducing unmanaged risk
Why It Matters
As AI agents become foundational to enterprise operations—particularly coding agents like Claude Code, Cursor, and Codex—organizations are adopting them rapidly without adequate security controls. AIR Security addresses a critical gap: while enterprises have firewalls protecting their networks, there is no equivalent protection for what enters an agent's context, leaving them vulnerable to prompt injection, supply chain attacks, and unauthorized actions.
Technical Details
- AIR Security's firewall discovers and evaluates every skill, plugin, MCP server, and add-on across an organization's AI agent supply chain, performing deep analysis against known agentic attack patterns before and after deployment
- The system screens for external instruction sources, hidden behaviors, typo-squatted packages masquerading as official developer tools, and vulnerable supply chains
- Continuous monitoring automatically revokes trust if a maintainer pushes a malicious update or an existing integration is compromised, with the ability to trace every agent and workflow depending on a given add-on
- The company's research identified AI Skills impersonating major companies like Anthropic and OpenAI designed to bypass security reviews and execute arbitrary code
- AIR offers a marketplace of pre-vetted, certified add-ons built from continuous evaluation of agentic activity across multiple customers
Industry Insight
- The AI agent security market is emerging as a critical infrastructure layer; enterprises adopting agentic tools like Claude Code and Cursor will need solutions like AIR to deploy with confidence, creating a significant commercial opportunity
- Supply chain security for AI add-ons will become a top priority for CISOs, paralleling the evolution of traditional software supply chain defenses like SBOMs and package signing
- The analogy of AI agents as the new operating system and add-ons as applications suggests that future security frameworks will need to treat agent context boundaries with the same rigor as network perimeters, likely driving regulatory and compliance requirements in the near term
Disclaimer: The above content is generated by AI and is for reference only.