返回新闻
安全AI Understanding 简报

AIR 凭借一个审查 AI 代理插件和操作的平台不再隐身

AIR 表示,它已经秘密推出了一个安全平台,旨在检查 AI 代理使用的技能、插件、MCP 和其他附加组件,然后在运行时监控代理活动。

5 min readRead the linked source
Source-provided image accompanying AIR exits stealth with a platform to vet AI-agent add-ons and actions
来源参考来源记录
出版商
air.security
来源链接
air.securityhttps://www.air.security/
来源类型
链接来源——主要来源状态尚未确定。
背景60 秒内了解这一点

从这里开始

关键术语

MCP(模型上下文协议)
一种开放协议,允许人工智能应用程序以标准方式连接到外部工具、数据源和上下文提供者。
人工智能代理
一种可以观察、推理并采取行动来实现目标的软件系统,通常使用工具和内存。
迅速的
提供给生成模型的输入指令和上下文。
测试一下自己AI 代理测验
Source video from air.security · shown with attribution.

发生了什么

AIR announced on September 1, 2026, that it was coming out of stealth with a security platform for AI agents. The company describes its core product as a “context firewall” that analyzes inputs entering an agent from skills, MCPs, plugins, websites and internal data.

AIR says it emerged from stealth on September 1, 2026, with a platform aimed specifically at securing AI agents and the external components they use. Its central product description is a “context firewall” positioned between an agent and the outside world. AIR says the system continuously analyzes and filters inputs entering an agent’s context, including skills, MCPs, plugins, websites and internal data, with the goal of stopping threats before they reach the agent.

The company divides the platform into four parts. AIR Control is described as governing an organization’s agent fleet, including sanctioned and “shadow” agents, through policies covering configuration, identity and permissions. AIR Filter is presented as an add-on firewall that vets skills, plugins, MCPs and subagents before installation. AIR Defend is intended to monitor agent actions and detect, respond to and protect against threats in real time. AIR Marketplace is described as a source of pre-vetted external and certified internal add-ons.

AIR frames skills, plugins and MCPs as the application layer around AI agents. In its terminology, skills are reusable instructions, plugins package skills and other components, and MCPs provide external tools, data and actions. The company says these add-ons can contain hidden behavior, injections, excessive permissions, unauthorized actions, externally loaded instructions, data-exfiltration paths or supply-chain weaknesses. These are AIR’s product and threat-model claims; the supplied source does not include independent testing of the platform.

The source also features an AIR research post dated August 27, 2026, titled “MCPJacking: 155 Hijackable MCPs Discovered Live in the Official MCP Marketplace.” AIR says its researchers found 155 MCPs relying on expired domains, registered those domains, published replacement MCPs and obtained remote execution on agents that trusted them. The page does not identify the affected marketplace in the supplied text, describe the full research method or provide independent confirmation. The source likewise does not state the investors, terms or closing date of the $50 million raise mentioned in the candidate headline.

来源详情: air.security ↗

为什么这很重要

AI agents increasingly depend on external tools and instructions, creating a security surface that AIR says conventional scanning may miss. The company’s approach focuses on the contents and permissions surrounding an agent, as well as the actions it takes.

The practical issue AIR is addressing is that an ’s behavior may depend on more than its underlying model. Instructions, tool definitions, permissions and retrieved information can influence what the agent does. If those components are compromised or overly broad, a trusted agent could be induced to take actions its operator did not intend. That makes the security of the surrounding agent ecosystem relevant to organizations deploying agents, not only the security of the model itself.

AIR’s product design reflects a lifecycle approach. It says add-ons should be checked before deployment, after updates and while running. That matters because an add-on can change over time, and a one-time review may not capture later changes or runtime behavior. AIR’s proposed combination of discovery, policy controls, preinstallation vetting and runtime protection could give organizations several points at which to restrict an agent, although the source does not show how those controls work in practice.

The company’s MCPjacking warning, if replicated, would illustrate a supply-chain problem for AI agents: a dependency that appears legitimate can become dangerous when its underlying external resource expires or changes ownership. AIR says the issue affected official marketplace entries and could allow remote execution. That claim points to a governance question for marketplaces and enterprises: who verifies ownership, maintenance and behavior of the external services that agents are allowed to trust?

There are important limits to what this announcement establishes. AIR provides no customer deployments, blocked-attack counts, false-positive rates, independent audit, pricing, availability timetable or detailed explanation of how its filters distinguish malicious instructions from legitimate agent behavior. Its security claims should therefore be treated as the company’s account of its product and research, rather than evidence that the platform has demonstrated effectiveness across enterprise environments.

Interactive Mechanism

互动机制:它实际上是如何运作的

以交互方式探索这一发展背后的基础技术。

Agent Lifecycle Stage:
1
User Intent & Planning: "Audit customer refund request #4092 and settle payment."
2
Tool Calling: Emits structured JSON call crm_get_transaction(id='4092').
3
Guardrail & Verification:🛡️ Paused: High-value action requires human operator sign-off.
4
Final Settlement: Refund recorded, email receipt dispatched, and audit log stored.
Core takeaway: An AI agent is not just a language model—it is a closed loop of planning, tool invocation, and environment feedback. Production systems require self-healing retries and strict human approval guardrails.
交互式概念检查+10 Points
AI Agents Quiz

An agent must create a draft calendar event for Tuesday at 2 p.m. Which evidence would establish the requested result?

接下来看什么

The main unanswered questions are whether AIR’s controls are deployed in production, how often they block real threats, and how the company’s claims about vulnerable MCPs withstand independent verification. The supplied source does not provide customers, pricing, test methodology or technical performance data.

First, watch for concrete evidence of deployment. AIR says it is offering demos and early access, but the supplied source does not name customers or describe a generally available release. Useful follow-up evidence would include the environments covered, the types of agents and add-ons supported, the permissions AIR can control, and whether organizations can inspect or appeal automated blocking decisions.

Second, watch for independent scrutiny of the MCPjacking research. The source says 155 MCPs were hijackable because they depended on expired domains, but it does not provide a list, reproduction details or the marketplace’s response. Verification would clarify how widespread the problem was, whether the affected entries remain vulnerable, and whether the result reflects a broader systemic weakness or a bounded set of dependencies.

Third, watch how AIR measures runtime protection. The company says AIR Defend can detect, respond to and protect against every action an agent takes, but the source gives no definitions or performance results. Important questions include what actions are observable, how quickly intervention occurs, what happens when the system is uncertain, and whether monitoring introduces delays or limits legitimate agent capabilities.

Finally, watch the company’s financing and commercial development separately from its technical claims. The candidate headline reports a $50 million raise, while the AIR source supplied here does not state the round size, investors or use of proceeds. Follow-up reporting should verify those terms and determine whether the funding supports research, marketplace expansion, enterprise sales or broader runtime-security development.

相关指南和测验

人工智能代理AI 伦理人工智能模型解释测试你所知道的——尝试免费的人工智能测验在我们的词汇表中查找人工智能术语关注AI监管追踪器
觉得这有用吗?