Back to News
SecurityAI Understanding briefing

AIR exits stealth with a platform to vet AI-agent add-ons and actions

AIR says it has emerged from stealth with a security platform designed to inspect the skills, plugins, MCPs and other add-ons that AI agents use, then monitor agent activity at runtime.

By 5 min readRead the primary source
Source-provided image accompanying AIR exits stealth with a platform to vet AI-agent add-ons and actions
The short version

AIR says it has emerged from stealth with a security platform designed to inspect the skills, plugins, MCPs and other add-ons that AI agents use, then monitor agent activity at runtime.

Official primary-source video from air.security · shown with attribution.

What happened

AIR announced on September 1, 2026, that it was coming out of stealth with a security platform for AI agents. The company describes its core product as a “context firewall” that analyzes inputs entering an agent from skills, MCPs, plugins, websites and internal data.

AIR says it emerged from stealth on September 1, 2026, with a platform aimed specifically at securing AI agents and the external components they use. Its central product description is a “context firewall” positioned between an agent and the outside world. AIR says the system continuously analyzes and filters inputs entering an agent’s context, including skills, MCPs, plugins, websites and internal data, with the goal of stopping threats before they reach the agent.

The company divides the platform into four parts. AIR Control is described as governing an organization’s agent fleet, including sanctioned and “shadow” agents, through policies covering configuration, identity and permissions. AIR Filter is presented as an add-on firewall that vets skills, plugins, MCPs and subagents before installation. AIR Defend is intended to monitor agent actions and detect, respond to and protect against threats in real time. AIR Marketplace is described as a source of pre-vetted external and certified internal add-ons.

AIR frames skills, plugins and MCPs as the application layer around AI agents. In its terminology, skills are reusable instructions, plugins package skills and other components, and MCPs provide external tools, data and actions. The company says these add-ons can contain hidden behavior, prompt injections, excessive permissions, unauthorized actions, externally loaded instructions, data-exfiltration paths or supply-chain weaknesses. These are AIR’s product and threat-model claims; the supplied source does not include independent testing of the platform.

The source also features an AIR research post dated August 27, 2026, titled “MCPJacking: 155 Hijackable MCPs Discovered Live in the Official MCP Marketplace.” AIR says its researchers found 155 MCPs relying on expired domains, registered those domains, published replacement MCPs and obtained remote prompt execution on agents that trusted them. The page does not identify the affected marketplace in the supplied text, describe the full research method or provide independent confirmation. The source likewise does not state the investors, terms or closing date of the $50 million raise mentioned in the candidate headline.

Source details: air.security

Why it matters

AI agents increasingly depend on external tools and instructions, creating a security surface that AIR says conventional scanning may miss. The company’s approach focuses on the contents and permissions surrounding an agent, as well as the actions it takes.

The practical issue AIR is addressing is that an AI agent’s behavior may depend on more than its underlying model. Instructions, tool definitions, permissions and retrieved information can influence what the agent does. If those components are compromised or overly broad, a trusted agent could be induced to take actions its operator did not intend. That makes the security of the surrounding agent ecosystem relevant to organizations deploying agents, not only the security of the model itself.

AIR’s product design reflects a lifecycle approach. It says add-ons should be checked before deployment, after updates and while running. That matters because an add-on can change over time, and a one-time review may not capture later changes or runtime behavior. AIR’s proposed combination of discovery, policy controls, preinstallation vetting and runtime protection could give organizations several points at which to restrict an agent, although the source does not show how those controls work in practice.

The company’s MCPjacking warning, if replicated, would illustrate a supply-chain problem for AI agents: a dependency that appears legitimate can become dangerous when its underlying external resource expires or changes ownership. AIR says the issue affected official marketplace entries and could allow remote prompt execution. That claim points to a governance question for marketplaces and enterprises: who verifies ownership, maintenance and behavior of the external services that agents are allowed to trust?

There are important limits to what this announcement establishes. AIR provides no customer deployments, blocked-attack counts, false-positive rates, independent audit, pricing, availability timetable or detailed explanation of how its filters distinguish malicious instructions from legitimate agent behavior. Its security claims should therefore be treated as the company’s account of its product and research, rather than evidence that the platform has demonstrated effectiveness across enterprise environments.

What to watch next

The main unanswered questions are whether AIR’s controls are deployed in production, how often they block real threats, and how the company’s claims about vulnerable MCPs withstand independent verification. The supplied source does not provide customers, pricing, test methodology or technical performance data.

First, watch for concrete evidence of deployment. AIR says it is offering demos and early access, but the supplied source does not name customers or describe a generally available release. Useful follow-up evidence would include the environments covered, the types of agents and add-ons supported, the permissions AIR can control, and whether organizations can inspect or appeal automated blocking decisions.

Second, watch for independent scrutiny of the MCPjacking research. The source says 155 MCPs were hijackable because they depended on expired domains, but it does not provide a list, reproduction details or the marketplace’s response. Verification would clarify how widespread the problem was, whether the affected entries remain vulnerable, and whether the result reflects a broader systemic weakness or a bounded set of dependencies.

Third, watch how AIR measures runtime protection. The company says AIR Defend can detect, respond to and protect against every action an agent takes, but the source gives no definitions or performance results. Important questions include what actions are observable, how quickly intervention occurs, what happens when the system is uncertain, and whether monitoring introduces delays or limits legitimate agent capabilities.

Finally, watch the company’s financing and commercial development separately from its technical claims. The candidate headline reports a $50 million raise, while the AIR source supplied here does not state the round size, investors or use of proceeds. Follow-up reporting should verify those terms and determine whether the funding supports research, marketplace expansion, enterprise sales or broader runtime-security development.

Related guides & quizzes

AI AgentsAI EthicsAI Models ExplainedTest what you know — try a free AI quizLook up an AI term in our glossary
Found this useful?