The Anti Job Board
Premium Drop
Live

$50M · AIR + 3 more

4 startups with founder intel, hiring signals, and outreach playbooks.

Hiring SignalsFounder ContactsOutreach Playbooks
Big Round
01 of 4
SeedHot

AIR

air.security · Tel Aviv, Israel · A context firewall that vets every skill, MCP and plugin an AI agent touches

$50MAI Security Researcher (agent add-on supply chain, skills/MCP/plugin abuse)Backend Engineer (inline filtering and interception at agent runtime)

What they're building

AIR sits inline between an agent and everything the agent reads. The framing on their own site is precise: "AIR sits between agents and the outside world. It continuously analyzes and filters every input into an agent's context — from skills, MCPs, and plugins to websites and internal data — stopping threats before they reach the agent." The insight is that the attack surface of an agent is not the model, it's the supply chain of things you bolt onto the model. The product decomposes into four pieces. AIR Control does fleet governance: find every agent actually running inside a company, including the ones nobody registered. AIR Filter is the vetting firewall over the three add-on primitives that matter right now — Skills (reusable task instructions), MCP servers (external capabilities), and plugins (bundles of both). AIR Defend handles runtime protection and threat detection once an agent is live. AIR Marketplace is the endgame: a source of pre-vetted add-ons, so the enterprise default becomes an allowlist rather than a scramble. The numbers behind the thesis come from their own scanning work. AIR says more than 17,800 public AI add-ons, carrying roughly 6.7 million installations, depend on untrusted external sources, and its whitelist currently filters out about 27% of available skills and add-ons as risky. They found fake Skills impersonating Anthropic and OpenAI that could execute arbitrary code. That is a package-registry problem wearing new clothes, and nobody has shipped npm-audit for agents yet. Demand so far is concentrated in financial services and pharmaceuticals, which is exactly where you would expect it: regulated industries that want agents in production but cannot sign off on an unbounded set of third-party tool calls.

Why this matters

Every serious enterprise agent deployment in 2026 runs on an add-on layer that resembles the early npm ecosystem: open publishing, no provenance, transitive dependencies, and installation counts in the millions. AIR's own scan puts 17,800+ public add-ons with ~6.7M installs on untrusted external sources, and 27% of what they see fails their bar. Those are the founders' figures, not an industry survey, but they match what the OWASP Agentic Skills Top 10 was created to catalogue, and Niv Hoffman co-leads that project. The timing argument is that the security layer for agents gets bought before the agents themselves get fully trusted, not after. Sequoia wrote a $10M check and Greenoaks wrote $40M within weeks of each other into a company founded in February. That is not patience, that's a land grab for a category the buyers are already asking about. Twenty-plus customers inside six months, with roughly a quarter of them large enterprises, says the pull is real rather than manufactured.

Unlock full intel

Get funding details, roles, outreach playbooks

View Plans
02 of 4
Seed

Paid drop

Subscribe to view full content

View Plans
03 of 4
Seed

Paid drop

Subscribe to view full content

View Plans
04 of 4
Seed

Paid drop

Subscribe to view full content

View Plans