Partnering with Air: Securing the AI Supply Chain

Every agent now imports plugins and skills from random places. Yair and Niv are building the software supply chain defenses for AI.

Every agent now imports plugins and skills from random places. Yair and Niv are building the software supply chain defenses for AI.

We met Yair Saban and Niv Hoffman before they had a company, a name, or a product. But as we ran our references on them across the Israeli cybersecurity ecosystem, the same answer kept coming back: they would be among the strongest founding teams in the country. One of the former commanders of Unit 8200 told us Yair was "the only person I have ever thought had everything required to one day command Unit 8200" — about as strong an endorsement as exists in Israeli tech. Niv is a technical outlier who led 8200’s most important vulnerability research department, building a network of elite technical talent. Yair finished his service on a Thursday, and we shook hands on a seed investment that Saturday, which tells you all you need to know about the pace at which this team operates.  

Well before Yair and Niv started building a defensive security product, they built MOAK, the "Mother of All KEVs," an agentic workflow that produces working exploits for freshly published vulnerabilities with no human in the loop. In one demonstration, MOAK exploited a React vulnerability in 21 minutes, versus the six days or so it takes a typical enterprise to roll out a patch. They released it publicly, to ring an alarm bell that the industry was badly underestimating the leverage attackers can now get from AI, and that defensive tooling needed to catch up.

The day developers started importing other people's packages instead of writing everything themselves, software acquired a supply chain. It then took two decades and a number of painful incidents, from log4j to Solarwinds, to build the machinery for inspecting what was coming in. Agents now have precisely the same problem, except that their supply chain is assembled at runtime and often nobody is inspecting it at all. An enterprise agent consumes skills, plugins, MCP servers, sub-agents, hooks, commands and rules — each running with the agent’s own permissions, inside a user’s environment, against a user’s data. Usually, they’re installed with the care most of us would give a browser extension.

Air has spent the past several months demonstrating the stakes. They wrote a deliberately malicious skill and watched multiple AI marketplaces wave it through as safe. Their Story of Skills research showed a researcher-built malicious skill reaching more than 26,000 agents through a trusted marketplace and social media, with every scanner clearing it. Then they published SkillJacking, which showed 925 live skills were pulling their dependencies and prompts from dead links; Air registered those links and took control of the roughly 134,000 agents that had installed them. Every public scanner they tested missed the problems completely.

The same day, Yair and Niv shipped ScanAir, an OWASP-aligned scanner for agentic skills. That sequence — find the hole, prove it, publish it, then ship the thing that closes it — is the pattern we like most about this team.

Today, Air has three products that between them cover the full lifecycle of an agent's add-ons. Air Filter vets every add-on before an agent is permitted to consume it, using static analysis, dependency checks and sandbox detonation. It then intercepts unsafe installations in real time and offers safe alternatives in their place. Air Defend monitors what agents actually do once they’re running and provides security operations teams with detection and response capabilities for agent behavior. Finally, Air Control handles posture and policy, from knowing which agents exist and what they’re allowed to touch, to revoking a bad skill across thousands of agents at once. Think of it like home security: Air Filter is the locks and the childproofing, Air Defend is the cameras and the person watching them, and Air Control is the panel by the door — every entry point accounted for, every code assigned, and all of them revocable at once.

Every couple of years, the best cyber talent coming out of Unit 8200 consolidates around a handful of teams. First it was Wiz, Cyera, and, Island; then it was Eon, Glow, Decart, and Kela; now it is Air. Yair and Niv are smart, hungry natural leaders who have proven their ability to attract extreme talent density; in only a few short months they have built a cracked team of the very best. We at Sequoia are proud to led their seed round, and to now double down in their Series A.

As enterprises move toward handing agents real authority over real systems, every CISO will be asked the same questions: what is our agent actually running, where did it come from, and who checked it? Today, few have complete answers. But Air is building the system of record that will.

share