As companies give AI agents access to an ever larger share of their systems, a new software supply chain is forming around the tooling those agents use: skills, plug-ins, MCP servers and the add-ons that let an agent interact with the internet. Israeli security startup AIR argues that this chain needs oversight, and it has come out of stealth with $50 million raised across two seed rounds to build the product.

The rounds closed within weeks of each other. The first raised $10 million led by Sequoia, the second $40 million led by Greenoaks. The company was founded by Yair Saban (CEO) and Niv Hoffman (CTO), veterans of Israel's Unit 8200 intelligence corps who worked on offensive cybersecurity. Wiz co-founder Yinon Costica, Eon co-founder Ofir Ehrlich, Cognition president Zach Frankel and Clay co-founder Varun Anand were among the angels who participated.

The driver signature analogy

Saban's argument rests on a historical comparison. “In the early 2000s, whenever you installed a driver, the driver didn't need to be signed. Today, every time you install a driver, you see a signature saying who signed it, because the driver is actually loading code into the kernel,” he says. That oversight, he argues, is missing for skills, plug-ins and MCPs: “It's the same mechanism, it's the same lesson, but we haven't learned it.”

The real risk he points to is not a direct attack. As agents start working more autonomously across databases and enterprise systems, attackers can poison the content an agent consumes rather than attacking the agent itself. The agent reads the malicious instruction from what looks like a legitimate data source.

Three layers of the product

  • Visibility: it discovers agents running across a company's environment and identifies tools not approved by IT, or employees using personal accounts.
  • Enforcement: it hooks into agents to intercept and analyse actions such as loading a skill or fetching content from the internet.
  • Whitelist: it checks the tools and add-ons an agent wants to use against a list AIR maintains by continuously evaluating publicly available components for changes and malicious behaviour.

The list needs continuous updating for a reason: a previously approved skill can become risky if a package it downloads changes, or if its developer's account is compromised. The company says it filters out about 27 percent of the add-ons and skills it finds online. AIR claims more than 20 customers, roughly a quarter of them large enterprises, with the strongest demand coming from heavily regulated industries such as financial services and pharmaceuticals.

The analogy has a limit. Driver signing was a standard imposed by operating system vendors acting as a central authority; the skill and MCP ecosystem has no such centre. Today the parties doing the vetting are security companies keeping their own lists, which makes the coverage and freshness of any whitelist directly dependent on the vendor.

A crowded field

AIR is far from alone here. Noma Security offers discovery, access controls and runtime monitoring for agents, MCP servers and skills. Zenity sells security and governance tools that work similarly. Astrix Security's identity platform also lets companies discover and control agents and MCP servers, while Operant AI offers agent protections alongside an MCP gateway. Venture money is chasing the category too: Zenity raised a $125 million Series C in August, and Noma raised a $100 million Series B last year.