AIR raised $50M because 27% of agent add-ons fail vetting
AIR came out of stealth with $50M to discover and vet the skills and add-ons AI agents install. It rejects about 27% of what it finds online.
AIR came out of stealth this week with $50 million raised across two seed rounds, and the number worth writing down is not the funding. It is 27. The company says roughly 27% of the agent skills and add-ons it finds online do not pass its vetting (TechCrunch). If you have let a coding agent install its own tooling this month, that is your hit rate too.
What actually happened
AIR was founded by CEO Yair Saban and CTO Niv Hoffman, both out of Israel's Unit 8200. The $50M arrived as a $10M first round led by Sequoia and a $40M second round led by Greenoaks, closing within weeks of each other. Angels include Wiz co-founder Yinon Costica and Clay co-founder Varun Anand. Valuation was not disclosed. The company has around 40 employees and 20-plus customers, about a quarter of them large enterprises, with the strongest pull from financial services and pharma.
The product does three things: discovers AI agents already running inside a company, continuously vets the skills and add-ons those agents pull in, and blocks anything not on the vetted whitelist.
Why unvetted agent add-ons matter for your business
Read that product description again and notice step one. Discovery. A $50M seed round exists because enterprises cannot answer the question "which agents are running here, and what did they install?" That is not an enterprise problem. That is worse at ten people, where nobody is even pretending to keep an inventory.
The threat model is simple and it is not hypothetical. An agent skill is a text file plus a permission grant. It runs with your agent's credentials, reads whatever your agent reads, and calls whatever your agent can call. Nobody code-reviews it, because it did not come through a pull request — it came through a marketplace listing that took four seconds to add.
You do not need AIR's platform to get most of the value. You need a list. Write down every MCP server, skill file and plugin your agents can load, who approved it, and what credentials it touches. Pin versions instead of tracking latest. Give agents scoped tokens, not the same key your app uses. Then re-read the list monthly, because the marketplace changed even if your config did not.
The uncomfortable part of the 27% figure is what it implies about the other 73%. Passing a vendor's filter is not the same as being safe in your environment, with your data, holding your keys.
Key takeaways
- AIR raised $50M across two seed rounds — $10M led by Sequoia, $40M led by Greenoaks — closing weeks apart
- Founded by Unit 8200 veterans Yair Saban and Niv Hoffman; ~40 employees, 20+ customers, valuation undisclosed
- The platform discovers agents running inside a company, vets their skills and add-ons, and blocks unapproved ones
- AIR says it filters out about 27% of the add-ons and skills it finds online
- Small teams get most of the benefit from an inventory: every MCP server and skill file, who approved it, what credentials it holds, pinned to a version
Your agent's plugin list is a dependency tree nobody reviewed. We inventory what your agents can load, scope their credentials down to the job, and pin the versions so a marketplace update is not a deployment. See how we lock it down, or send us what your agents are running today.
Sources: TechCrunch.
- #ai-agents
- #supply-chain
- #mcp
- #security
- #agent-skills
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Thinking Machines at $40B: bet on what actually shipped
Accel is reportedly in talks to lead a $1B round for Thinking Machines at $40B on $100M revenue. The round is noise. The open weights are the durable part.
Read itMAI-Transcribe-2 drops transcription to $0.10 per hour
Microsoft's MAI-Transcribe-2 launched at $0.10 per hour of audio with 60 languages and diarization. The model is a commodity — your pipeline is the lock-in.
Read it