A skill is not just a button

AIR describes its product as sitting between an AI agent and the outside world, including skills, MCPs, plug-ins, websites and internal data. An MCP server is simply a connector that lets an AI tool talk to another system. That can be handy. It can also mean that one cheerful install screen now has a path toward files, messages, customer information or an action you would normally do yourself.

The point is not that every add-on is dangerous. Most people already make this kind of decision with phone apps, browser extensions and shared documents. The mistake is acting as if an AI helper is different because the permission arrives wrapped in a useful sentence. “It can organize your inbox” is not the permission. The permission is whatever access makes that possible.

AIR says it has found and filtered out about 27% of the skills and add-ons it scans. That is a vendor-reported number, not a public estimate of how many tools are unsafe. Still, it names the part worth noticing: an add-on can change after you first approve it, or pull in something else later. Installation is not the end of the decision.

Three questions before you connect it

First: what one job is this supposed to remove from my week? “Help with everything” is not a job. “Turn the same five support notes into a draft I review” is. A narrow first use makes it easier to tell whether the tool earned its access.

Second: what can it read, change or send? Check the actual permission screen and the service it connects to, not only the marketplace description. If the answer is vague, do not connect it to the place where the vague answer would matter most. A research helper can start with public pages. An email helper can begin with drafts, not sending.

Third: what happens when you remove it or it changes? Look for a way to revoke access, delete its connection and find the work it created. If nobody can explain that in plain language, the add-on is asking you to accept its cleanup as a future surprise.

Start where a mistake is cheap

Try a new AI tool on a small, reversible task before it touches the folder everybody relies on. A local checklist, a public research question or a sample document will tell you more than a polished demo. You are looking for the boring facts: does it do the stated job, does it ask for access it does not need, and can you switch it off without hunting through three account pages?

That is also kinder to the people around you. A teammate should not discover that an assistant can see a shared drive only after it has summarized something private. A customer should not be the first person to learn that a helpful connector can send a confident wrong answer. Small tests are not mistrust. They are how you keep one convenient tool from becoming another cleanup job.

Noah would keep the first try narrow. Ivy would count the new support work.

Noah Park’s test is practical: pick one task you already understand, use non-sensitive material, and see whether the add-on leaves behind a result you can inspect without becoming its full-time mechanic. If it cannot save a little time on a small job, it has not earned a bigger one.

Ivy Chen looks at the team cost. A tool is not reducing admin if one person has to answer every permission question, explain every odd result and clean up every connection when someone leaves. The right fit should make the repeated work smaller without quietly creating a new support desk.

Neither view requires perfection. It asks for a sensible order: understand the job, limit the reach, keep a way out. That is enough to let useful AI tools help without handing them the keys to the whole day.