Agent Plugins 1.0: Open Packaging, Closed Distribution
Bentoshi
On August 6, 2026, five platform operators shipped a standard instead of debating it. Amazon, Microsoft, OpenAI, Vercel, and Cursor adopted Agent Plugins 1.0.0 simultaneously — an open, vendor-neutral format for packaging Agent Skills and Model Context Protocol (MCP) servers into portable plugins. VS Code, GitHub Copilot, Cursor, ChatGPT, and Kiro integrated it at launch. Google joined as a core maintainer the same day, with Kevin Hou leading from the Google Developers side, shipping two plugin producers in Agents CLI and Data Agent Kit while stopping short of a client entry.
This was not a proposal. Not a white paper. It shipped as working code.
The contrast is instructive. The IETF DAWN working group spent July in Vienna debating the discovery layer beneath the agent ecosystem. Its charter was deferred at IETF 126 despite twelve pre-charter Internet-Drafts. The industry did not wait for consensus. It built the packaging layer, left discovery unresolved, and announced its answer before the standards bodies could schedule another meeting.
I have watched standardization efforts in adjacent infrastructure fail for two cycles. The pattern is constant: consensus processes accrete process, not throughput. Agent Plugins 1.0 is the counterexample — a shipping standard governed by individuals rather than institutional procedure. The Technical Steering Committee includes Clare Liguori of AWS, Roshan Sadanani of Cursor, Harald Kirschner of Microsoft, Gav Verma of OpenAI, and Jonathan Hefner of Vercel as lead core maintainer. The project name, logos, domains, and GitHub organization sit with a neutral entity. The spec is CC-BY-4.0. The code is Apache-2.0. Governance seats belong to individuals, not companies, preventing any single vendor from holding a majority.
Macro trends crush micro-protocols. A packaging standard adopted by the clients that reach the largest enterprise buyers is a macro event — one that will determine the agent economy's distribution structure long before any DAWN protocol resolves its discovery-layer debate. My 2025 protocol-design work gives me a specific lens. I structured a decentralized economic protocol for autonomous AI agents, secured a $1.2 million grant from a European tech consortium, and designed tokenomics where agents trade compute resources via micro-payments. The hardest problem was never consensus. It was distribution. Agent Plugins 1.0 reproduces that lesson at industry scale: the specification is the easy part. The route to market is the contested territory.
Read the spec's exclusions. That is where the economics live.
Agent Plugins 1.0 deliberately omits installation mechanisms, distribution protocols, provenance verification, permission models, sandboxing requirements, and marketplaces. Packaging is normalized. Distribution is not. Each platform operator controls how agent skills reach its users. The standard defines no registry, no marketplace, no discovery layer, no revenue path. This is not an oversight. It is structure.
The gatekeeper calculus is deterministic. The entity that ships the client controls distribution. The entity that controls distribution extracts rent. Developers building high-value agent skills are not simply adopting a standard — they are selecting which gatekeeper governs their access to enterprise buyers. VS Code's plugin flow is not Cursor's. ChatGPT's discovery experience is not Kiro's. Each client builds its own channel. Each channel carries its own commercial terms. The technical spec is open. The business model is a collection of proprietary chokepoints.
For enterprise technology leaders, the switching-cost equation changed on August 6. Adopting Agent Plugins 1.0 is cheap. Migrating a skill portfolio across divergent gatekeepers is expensive. This is where my 2023 CBDC pilot experience sharpens the analysis. At the National Bank of Poland, I directed a team of five developers optimizing a permissioned ledger architecture to 10,000 transactions per second. State-controlled ledgers work precisely because distribution is unified. The agent economy is choosing the opposite arrangement — standardized packaging with fragmented access. The efficiency differential will appear in enterprise procurement decisions within two quarters.
The fragmentation is structural, not accidental. TSC neutrality is a governance commitment, not an economic one. Compatibility at the file-format level does not produce interoperability at the distribution level. When I analyzed the Terra collapse in 2022, I linked crypto-liquidity cycles to global M2 contractions and concluded that DeFi functions as high-leverage shadow banking. The structural lesson transfers cleanly: infrastructure that appears standardized while channeling value through fragmented intermediaries replicates systemic fragility. The packaging standard reduces format lock-in risk and increases distribution lock-in risk simultaneously. Code enforces; policy dictates. Both now favor the gatekeepers.
The conspicuous absence is Anthropic. Claude Code is not among the launch clients. No Anthropic representative sits on the TSC. This is notable because Anthropic authored the underlying Agent Skills specification and the .claude-plugin format that shaped the coalition's standard.
The technical divergence explains the seat. Claude Code's plugin format supports custom subagents, hooks, LSP servers, and background monitors — a richer feature set than the coalition's portable-but-minimal approach. The format ties to Anthropic's client structure via claude.md rather than the agents.md convention the coalition adopted. Anthropic is betting on depth within a single client. The coalition is betting on breadth across many.
For machine-centric valuation, this fork is the first structural test of the agent economy. The value metric is not token price or user count. It is machine transaction velocity. Anthropic's richer format captures more velocity per agent. The coalition's standard captures more agents per format. Which derivative you prefer depends on whether you weight intensity or reach. My backtesting framework from the 2020 DeFi liquidity audits — where I demonstrated that impermanent-loss risk for stablecoin pairs was systematically underestimated, producing a whitepaper downloaded over 5,000 times — conditions me toward the reach side. Broad adoption generates the statistical base. Richer formats generate the performance outliers. The standard's minimalism is its strength and its ceiling.
The trust gap is the immediate operational problem. Version 1.0 contains no provenance model. Per VS Code documentation, plugins are implicitly trusted at the moment of installation. No cryptographic signatures. No standardized permission model. No sandboxing requirements in the spec. For a system designed to package executable capabilities for autonomous agents, this omission creates tail risk that enterprise security teams will not accept.
The resulting demand is for governance layers. OpenAI Presence, launched in July as a governance-focused control plane for enterprise agent behavior, is positioned to supply exactly that. As MCP gateways crystallize into enterprise infrastructure, the stack pattern is predictable: open packaging format below, proprietary control plane above. Compliance pressure converts open infrastructure into a market for closed governance.
This is not a failure of the standard. It is the market pricing trust. I saw the same structure in crypto exchange infrastructure — standardized assets, proprietary custody, and regulatory arbitrage between venues. In 2024, my proprietary algorithm tracking institutional inflows across fifteen exchanges correlated altcoin outflows with S&P 500 volatility, predicting the 15% correction that followed. The data showed capital concentrating in venues with the strongest compliance surfaces. The agent economy will replicate that concentration. Platforms with robust permission models and audit trails capture the premium. Those without carry the liability discount.
The governance question is whether competing implementations remain genuinely compatible. Individual TSC seats are the right starting point. The enforcement mechanism is behavioral. If Vercel and Microsoft ship materially divergent installation and discovery experiences, the standard's openness becomes cosmetic. If a single unified registry emerges, the gatekeeper problem relocates into one entity. Both outcomes preserve the standard. Neither preserves the open market.
Openness at the packaging layer does not mean openness at the distribution layer. That is the central distinction. The coalition has lowered the barrier to building agent skills. The market those skills serve will determine whether the agent economy becomes an open ecosystem or a collection of walled gardens sharing a common file format.
I am tracking three metrics. First, whether any registry or marketplace emerges to consolidate distribution — that becomes the next monopoly. Second, whether Anthropic's richer format forces the coalition to expand its minimal scope — the spec's future is contested by its largest non-member. Third, whether enterprise control-plane revenue outgrows plugin developer revenue — the ratio that reveals who captures value in this stack.
The agent economy received its npm moment on August 6. npm's history is instructive: the package manager standardized distribution, and centralization followed. The Agent Plugins coalition standardized packaging and deliberately avoided distribution. That choice preserves optionality. It also preserves the rent layer. Standardization is a competitive strategy dressed as infrastructure. Code enforces; policy dictates. The market prices the difference. The next phase will reveal which side of that equation governs the agent economy's builders — and who collects the fees.