AI Agent Firewall Startup AIR Security Emerges From Stealth With $50 Million
Add-ons that plug into AI agents like Claude Code, Cursor, and Codex can carry hidden malicious instructions or ask for far more access than they need. Researchers found skills in the wild pretending to be from Anthropic or OpenAI so they slip past review and run attacker code once installed.
- Severity
- Not scoredNo CVSS score recorded
- Affects
- AIR Security+4 more
How it works
An add-on's publisher can name it and describe it to look like it comes from a trusted AI company, and an agent that installs it follows whatever instructions and permissions the add-on carries without a human checking each one.
What to do
Ask your organization's security team whether AI agents in use install skills, plugins, or MCP servers from outside sources and whether those installs are reviewed before use.
AIR Security's new firewall product is one option enterprises can add to screen add-ons before they reach an agent, and vendor-verified add-on sources should be checked directly with Anthropic or OpenAI when in doubt.
Technical details
Affected software: AIR Security, MCP servers, Claude Code, Cursor, Codex
AIR Security, founded by CEO Yair Saban and CTO Niv Hoffman, launched its AIR firewall out of stealth with $50 million led by Sequoia Capital and Greenoaks. The firewall inspects AI skills, plugins, and MCP servers for malicious instructions, excessive permissions, and software supply chain risk before they reach an agent's context. Its research identified over 17,800 public AI add-ons, representing 6.7 million installs, that rely on untrusted external instruction sources, and found AI skills impersonating Anthropic and OpenAI that were built to bypass security review and execute arbitrary code. Ryan Knisley, former CISO at Disney and Costco, joined as chief strategy officer.