17,800+ Risky AI Add-ons Expose Gaps in AI Agent Security
The emergence of AIR Security highlights a rapidly growing and underappreciated attack surface: third-party AI plugins, skills, and add-ons that can be weaponized to impersonate legitimate companies, bypass review processes, and execute malicious code. Much like the early days of browser extensions or mobile app stores, the AI ecosystem has expanded faster than security vetting mechanisms can keep pace. Organizations deploying AI agents are unknowingly inheriting supply chain risks through excessive plugin permissions and unvetted third-party integrations. This matters because compromised AI agents can act autonomously at scale, amplifying the damage of any single malicious component far beyond what a traditional software vulnerability might achieve.
Tactical Insight
Immediate actions
- Audit all AI plugins, add-ons, and extensions currently in use across your organization and remove any that cannot be verified as legitimate.
- Apply the principle of least privilege to AI agent permissions, revoking any excessive access granted to plugins or connected services.
Long-term improvements
- Establish a formal vetting and approval process for AI add-ons before deployment, analogous to enterprise app store controls.
- Implement AI-specific firewall or gateway controls that inspect plugin instructions, server connections, and behavioral patterns for anomalies.
- Integrate AI agent supply chain risk into your existing third-party vendor risk management program.
Detection measures
- Enable continuous monitoring and logging of AI agent actions, plugin calls, and external API interactions to detect anomalous or unauthorized behavior.
- Subscribe to threat intelligence feeds focused on malicious AI extensions and impersonation campaigns targeting AI platforms.