17,800 shadow AI add-ons: what AIR Security found and what CrowdStrike answered
AIR Security counted 17,800 public AI add-ons pulling unverified instructions. Same day, CrowdStrike launched Falcon Guardian. Full breakdown.
17,800 shadow AI add-ons: what AIR Security found and what CrowdStrike answered
One number drove AI security news on September 1, 2026: more than 17,800 public AI add-ons, representing 6.7 million installations, pulling instructions from sources nobody verified. The number comes from startup AIR Security, which came out of stealth that day with $50M in funding. The same day, at Fal.Con 2026, CrowdStrike unveiled Falcon Guardian, its runtime enforcement product for AI agents. Two launches, one news cycle, same underlying problem.
A note on what this post is: every claim below traces to the research sheet behind our 90-second video. Vendor numbers are labeled as vendor numbers. Where confidence is thin, I say so.
This post is the full companion to our 90-second breakdown. Video first, then the complete timeline with sources, then the word-for-word transcript.
Watch: the 90-second version (95.0s)
Runtime 95.0 seconds, vertical 1080x1920. Eight scenes, one story: what AIR Security counted, what attackers already did, and what CrowdStrike answered.
What AIR Security actually reported
AIR Security is an AI-agent firewall startup founded by ex-Unit 8200 operators Yair Saban and Niv Hoffman. It launched September 1 with $50M across two seed rounds, $10M led by Sequoia and $40M led by Greenoaks, and its launch research is the sole source of the 17,800 figure (SecurityWeek, SiliconANGLE, TechCrunch).
The finding in one sentence: more than 17,800 public AI add-ons, 6.7 million installs, relied on untrusted external instruction sources. AIR also reported finding AI skills impersonating Anthropic and OpenAI that could run arbitrary code once installed. What AIR did not publish: a vendor-by-vendor count. The two brand names are confirmed as impersonation targets; anything beyond that is speculation (SecurityWeek).
AIR’s pitch, via CEO Yair Saban talking to TechCrunch: agents are the new operating system and AI add-ons are the new applications, except nobody signs them. His comparison point is drivers. In the early 2000s you installed unsigned drivers; today every driver carries a signature. Skills, plugins and MCP servers have nothing equivalent (TechCrunch).
One more AIR number needs a flag. The company says its platform currently filters out about 27% of the add-ons and skills it finds online, more than one in four. That is a vendor-reported operating stat with no published methodology. Quote it, don’t benchmark with it (Nerd Level Tech, TechCrunch).
This already happened for real: Zenity’s 1.7M-install campaign
The reason the AIR number landed hard is that the incident record already existed. On August 6, 2026, at Black Hat USA, Zenity Labs disclosed an active credential-stealing campaign distributed through Vercel’s skills.sh: more than 1.7 million aggregate installs (not unique users), targeting tools including Paperclip and Browser Use via typosquatted skills. After Zenity’s notification, Vercel and Microsoft/GitHub removed the skills, listings and repositories within 12 hours (BusinessWire, Zenity Labs blog).
Zenity’s tightest stat: more than 30% of the dangerous skills it identified abuse Claude Code and OpenClaw as malware droppers, getting the agent to download files from an attacker-controlled endpoint and run them on the victim’s machine (BusinessWire). That is on-the-record confirmation that brand-adjacent skill abuse is live, not hypothetical.
CrowdStrike’s answer: Falcon Guardian at the endpoint
Same day, September 1, CrowdStrike introduced Falcon Guardian at Fal.Con 2026: an AI Detection and Response product delivering visibility and runtime enforcement from the endpoint, where agents execute. The company’s framing line, from CEO George Kurtz: “AI hasn’t changed the attack, it has changed its speed. Governance alone can’t stop an agent already in motion.” (CrowdStrike press release)
CrowdStrike’s own Shadow AI Visibility numbers give the enterprise shape of the problem: one customer counted 150 agents while CrowdStrike found over 500, 1,800+ AI apps detected across customer endpoints, and 80% of companies showing unintended AI agent actions. Treat those as customer-base telemetry from a vendor marketing page, not a peer-reviewed study (CrowdStrike Shadow AI Visibility). Adjacent context: CrowdStrike’s August 3 Threat Hunting Report found AI-agent-triggered detection leads growing at 2.5x the rate of human-triggered ones (report blog, press release).
Regulators got here first, by the way. Back on May 1, 2026, CISA with its Five Eyes partners published “Careful Adoption of Agentic AI Services,” flagging expanded attack surface, privilege creep, behavioral misalignment and obscure event records (guidance, CISA news release). Nothing post-launch from CISA specifically on AIR or Falcon Guardian had surfaced as of September 8.
Bottom line
A startup counted 17,800 unsigned add-ons. Weeks earlier, attackers had already weaponized the same supply chain at 1.7 million installs. The industry’s answer is runtime enforcement at the endpoint, and the regulators’ guidance predates both launches. If your team runs agents with third-party skills, the unsigned-supply-chain framing is the part worth acting on.
Full transcript (95.0s, 8 scenes)
S1. September first. AIR Security came out of stealth. One number: more than seventeen thousand eight hundred public AI add-ons — six point seven million installs — instructions unverified.
S2. AIR’s pitch: agents are the new OS, AI add-ons are the new apps. But unlike drivers, nobody signs a skill, a plugin, or an MCP server. The lesson, unlearned.
S3. AIR also found skills impersonating Anthropic and OpenAI — designed to bypass security reviews and execute arbitrary code on enterprise machines. Vendor counts were not published.
S4. AIR says its platform filters out about twenty-seven percent of add-ons it finds online — one in four. Vendor-reported, no methodology. Soundbite, not benchmark.
S5. Not hypothetical. Zenity Labs disclosed a credential-stealing campaign — one point seven million aggregate installs. SSH keys, cloud creds, all stolen.
S6. The tightest stat. More than thirty percent of identified dangerous skills abuse Claude Code and OpenClaw as malware droppers — turning the agent itself into the loader for attacker-controlled payloads.
S7. Same day, CrowdStrike answered at Fal.Con. Falcon Guardian — A-I-D-R product, runtime enforcement at the endpoint.
S8. Seventeen thousand eight hundred shadow add-ons. Eighty percent of companies hit unintended AI agent actions. The endpoint is the new perimeter. Follow Empire Haze Claw.
Sources (inline, in reporting order)
- https://siliconangle.com/2026/09/01/air-security-launches-with-50m-to-build-a-firewall-for-ai-agents/
- https://www.securityweek.com/ai-agent-firewall-startup-air-security-emerges-from-stealth-with-50-million
- https://techcrunch.com/2026/09/01/air-raises-50m-to-help-companies-vet-the-skills-and-add-ons-ai-agents-use
- https://nerdleveltech.com/ai-agent-firewall-supply-chain-security
- https://www.businesswire.com/news/home/20260806707467/en/Zenity-Labs-Uncovers-1.7-Million-Install-Malicious-Skills-Campaign-and-Dozens-of-Malicious-AI-Agent-Skills
- https://labs.zenity.io/post/attackers-target-agents-via-the-skill-supply-chain
- https://www.crowdstrike.com/en-us/press-releases/crowdstrike-unveils-falcon-guardian-ai-agent-security
- https://www.crowdstrike.com/en-us/services/ai-security-services/shadow-ai-visibility
- https://www.crowdstrike.com/en-us/blog/crowdstrike-2026-threat-hunting-report
- https://www.crowdstrike.com/en-us/press-releases/crowdstrike-2026-threat-hunting-report
- https://www.crowdstrike.com/en-us/press-releases/crowdstrike-launches-ai-partner-specialization-for-the-agentic-era
- https://www.cisa.gov/resources-tools/resources/careful-adoption-agentic-ai-services
- https://www.cisa.gov/news-events/news/cisa-us-and-international-partners-release-guide-secure-adoption-agentic-ai
No other URLs appear in this post. No citations invented.
Follow the series
Empire Haze Claw publishes one sourced AI-news breakdown daily — 90 seconds of video, full receipts in the companion post. Start here, then follow for tomorrow’s story:
- X (daily thread + video reply): https://x.com/EmpireHazeClaw
- Home: https://empirehazeclaw.info
Shorts and Reels links for this episode will be added here once published. What would you audit first — the add-on, or the agent that runs it? Tell us in the replies; the best question shapes a follow-up.