17,800 AI Add-Ons Take Orders From Sources Nobody Verified. Now the Endpoint Can Block Yours

September 7, 2026
11 min read

September 7, 2026
11 min read
Most weeks the agent news is a capability. This week it was a gate.
On 1 September, two things launched within hours of each other. CrowdStrike unveiled Falcon Guardian, which inventories every AI agent running on a machine — including the ones nobody registered — and blocks the agents nobody approved. And AIR Security came out of stealth with $50 million to build an inline firewall that screens what enters an agent's context before the agent acts on it.
Read separately, two product announcements. Read together, they are the same sentence from both ends: agents are now arriving in companies faster than anyone can account for them, and the response has moved from policy to enforcement.
Two launches, 1 September 2026
One built to see and stop agents, one built to check what they load
Note who is buying. AIR reports 20-plus companies already using the platform, about a quarter of them large enterprises, with the strongest demand from financial services and pharma. Those are the two industries that historically decide what everyone else's procurement looks like eighteen months later.
Not the funding. Not the enforcement. This one:
Shadow AI agent. Known and shadow, across Windows and macOS.
"Shadow AI agent" is now a named category inside a security product, with a live inventory attached and a block button next to it.
That phrasing has a history. "Shadow IT" was what the industry called bottom-up SaaS adoption for a decade — and bottom-up SaaS adoption was, for that same decade, the single most reliable distribution strategy a software founder had. You did not sell to the CIO. You got installed by the person who needed the thing, and by the time procurement noticed, you had four hundred seats and an internal champion.
Every agent startup I know is running some version of that playbook right now. An engineer installs your CLI. A team wires up your MCP server. Nobody files a ticket.
The uncomfortable symmetry
A product now exists whose explicit job is to produce a list of exactly those installs, name the person who deployed each one, and stop the ones that were never approved. Your distribution strategy and its detection logic are describing the same event. That does not mean you are the threat it was built for — but the inventory does not know that on day one, and neither does the security analyst reading it.
It is easy to read AIR's number as a story about bad actors publishing malicious skills. Some of it is: fake add-ons wearing Anthropic and OpenAI branding to get past review is straightforwardly an attack.
But most of 17,800 is not malice. It is add-ons that fetch their instructions from somewhere else at runtime — a URL, a repo, a hosted config — because that is a perfectly sensible way to ship updates without republishing. The supply chain is doing what supply chains do.
The problem is what that means once an agent is on the other end. A library you install executes the code you audited. An add-on that pulls instructions at runtime executes text that arrives later, inside a context window that has your credentials and your tool permissions attached to it. It is not a dependency in the sense your dependency scanner understands. It is an open channel into the part of your system that acts.
I wrote about the identity half of this when the MCP roadmap started designing the human out of the loop. This is the other half: not who the agent is, but where its instructions came from.
The same research is a warning pointed the other way. Most founders shipping agent products are also, quietly, running twenty of somebody else's add-ons in their own stack.
The full forensic timeline of the OpenAI agent breach is the version of this that already happened, and the shape was the same: the agent was not compromised, the thing it trusted was.
This is not the end of bottom-up. Enforcement is a capability that has to be turned on, tuned, and staffed. Most companies will run discovery for a long time before they run blocking, because a false positive that kills an engineer's coding agent is an expensive ticket. The inventory arrives well before the block does.
Two launches on one day is a signal, not a market. Vendors cluster announcements around conferences, and Fal.Con was that week. What makes it worth writing about is that one is an incumbent adding enforcement and the other is a six-month-old company raising $50 million on the same premise — but that is still two data points, and I am reading a direction into them.
AIR's 17,800 is their own research. It comes from a company selling the solution to the thing it measured, which does not make it wrong — the impersonation finding is concrete and checkable — but the framing of what counts as "untrusted" is theirs, and the 27% filter rate suggests the raw number was noisier still.
The interesting thing about 1 September is not either product. It is that the question changed from "can agents be trusted" to "which agents are running here, who put them there, and should they be". That is an operational question, and operational questions get answered by tools, and tools get bought.
For founders shipping agents, the practical shift is small and annoying: the moment where nobody noticed you was load-bearing, and it is being instrumented away. What replaces it is not worse, just slower and more explicit — an approval artefact, a named owner, a scope you can describe in one page.
For founders running agents, the shift is larger. Your dependency list is now also an instruction list, and the second one was never reviewed by anyone. 17,800 add-ons and 6.7 million installations is not a story about other people's security posture. It is a decent estimate of how many of those channels are open inside ordinary companies right now, including yours.
Sources: CrowdStrike press release, "CrowdStrike Unveils Falcon Guardian to Secure AI Agents Where They Execute" · SiliconANGLE on Falcon Guardian · SiliconANGLE on AIR Security's launch · SecurityWeek on the AIR Security round · Product capabilities, funding and research figures are as reported; the distribution argument and the cautions in section 6 are mine.
IdeaToMVP Academy
4-week live cohort for founders. Learn to ship AI agents, scope MVPs, and automate your business — taught by the same team that writes these guides.