WangDou logo
WangDou

17,800 AI add-ons are quietly pulling instructions from outside — a six-month-old startup just raised $50M to block them

2026-09-01·WangDou AI Express·AI / Security / Agents

That MCP server you installed. That skill. That plugin. It updated yesterday — did you notice? A company founded in February scanned the ecosystem, found 17,800 AI add-ons pulling instructions from outside, and walked away with $50 million.

Three Key Facts

$50 million across two rounds, closed in six months. AIR Security launched publicly on September 1: Sequoia led an initial $10M, Greenoaks led a $40M follow-on, with Swish Ventures and Netz Capital participating. Angels include Wiz co-founder Yinon Costica, Clay co-founder Varun Anand, Cognition president Zach Frankel, and former White House cyber adviser Anne Neuberger. Founded February 2026 by Yair Saban and Niv Hoffman, both Unit 8200 alumni, with roughly 40 employees.

The scan results are the real headline. AIR found more than 17,800 public AI add-ons drawing unverified instructions from untrusted external sources, across roughly 6.7 million installations. Uglier still: brand impersonation, with AI skills posing as official Anthropic and OpenAI products to clear security review and then execute arbitrary code. In live customer environments, the platform filters out about 27% of the add-ons it discovers.

The product guards what comes in, not what goes out. AIR positions itself as an inline firewall for agents: continuously discovering and evaluating every skill, plugin, MCP server and add-on in an organization, before and after deployment. When one is judged malicious, vulnerable, or unapproved, security teams can trace every dependent workflow and revoke it. Over 20 companies use it today, about a quarter of them large enterprises, with financial services and pharma showing the strongest demand.

WangDou's Take

The number that should sting is 27%. Not 2.7 percent — more than one in four agent extensions running inside real companies shouldn't be there. For two years the industry has been celebrating the MCP ecosystem's explosion, hundreds of new plugins and connectors a day, and nobody stopped to ask who wrote them, what they fetch on each update, and who is reading your context once they're installed. Now we have an answer: 17,800 components pulling from untrusted sources across 6.7 million installs, some of them wearing an OpenAI or Anthropic badge to get waved through review. This is the npm supply-chain poisoning story running again, with one substitution — the poisoned target isn't the build pipeline, it's the model's input. Security has always worked this way: a wave of technology sprints ahead, then a wave of companies shows up selling locks. Sequoia and Greenoaks putting $50M into a forty-person shop inside six months isn't a bet on this particular team. It's a bet that the agent supply chain is a hole big enough that somebody is going to get paid to plug it.

Source: SiliconANGLE, Calcalist, Dealroom

Comments

Log in to comment
    This briefing was auto-written by WangDou AI Express for reference only; corrections welcome if you spot a factual error.
    指挥舱👽