JFrog Ltd., the Liquid Software company and creators of the JFrog Software Supply Chain Platform, today unveiled a new suite of capabilities to secure and govern the agentic workforce at swampUP 2026. Announced from Sunnyvale, California and New York, the new JFrog Platform capabilities help ensure AI agents only consume and produce trusted, scanned artifacts using a single source of truth by natively connecting AI assets to the JFrog Platform and implementing an always-on AgentSecOps workflow.
AI coding agents not only write software at machine speed but also consume software at scale. The DevSecOps controls built over a decade assumed a human developer was at the keyboard, but a software supply chain run by agents doesn't stop for reviews. Agents make decisions about finding and pulling dependencies without a human in the loop, installing traditional packages and AI assets such as skills, context files and MCPs from various sources. From sandbox escapes to compromised configuration files, vulnerabilities in coding agents are real and security can't be bolted on after the fact.
Gartner's Hype Cycle for Agentic AI, 2026, states only 17% of organizations have deployed AI agents to date, yet more than 60% expect to do so within the next two years. However, Gartner also predicts that over 40% of agentic AI projects will be canceled by the end of 2027 due to escalating costs, unclear business value, or inadequate risk controls.
"AI coding agents not only write software at machine speed but also consume software at scale. The DevSecOps controls we built over a decade assumed a human developer was at the keyboard. Today, that assumption has broken - a software supply chain run by agents doesn't stop for reviews. Agents make decisions about finding and pulling dependencies without a human in the loop, installing traditional packages and AI assets such as skills, context files and MCPs from various sources," said Yoav Landman, Co-founder and CTO, JFrog. "In order to scale agents responsibly and make sure they are compliant, these dependencies must come from a trusted source. The only way to achieve that is by ingraining an intrinsic immune layer directly into the software supply chain that guarantees every input consumed by agents originates from a single, trusted, secure system of record."
The new enhancements to the JFrog Platform ensure customers can secure, govern, and control AI agents at scale. Protect What Agents Consume includes AI Asset Scanning to index, scan, and block risky or malicious models, MCPs, skills, and plugins with proactive semantic scanning of markdown files. Agent Plugins Registry governs coding-agent plugins using Agent Guard ensuring agents across Claude Code, Cursor, VS Code only use vetted plugins. Agent Package Manager Registry integrates the Microsoft-led APM standard into Artifactory to package, version, and manage AI assets including prompts, skills, and MCP servers with full dependency tracking. Agent Guard natively enforces project-scoped allow/deny policies from AI Catalog inside developer tools.
Control How Agents Build includes JFrog Agent Plugin connecting agents to JFrog Platform to bring organizational standards directly to agent workflows. Agent Package Resolution authenticates and provides trusted path for agents to resolve dependencies through Artifactory. Network-Layer Protection with Traffic Controller and SASE partners Cloudflare, Netskope, Zscaler blocks public registry calls at network layer, rerouting all traffic through Artifactory for visibility and control.
"By deploying JFrog, we've seen fewer vulnerabilities, which has given our developers more time to focus on building new applications. With all our development teams on one platform, the process is centralized and streamlined," said Billy Norwood, Chief Information Security Officer at FFF Enterprises. "We're handling risks further up the chain by shifting left, so vulnerabilities are remediated before anything gets published."
About JFrog
JFrog Ltd. the creators of the unified DevOps, DevSecOps, DevGovOps, and AgentSecOps platform, is on a mission to create a world of trusted software delivery without friction from development to production. Driven by a “Liquid Software” vision, the JFrog Platform is a software supply chain system of record that is designed to power organizations as they build, manage, govern, and distribute secure software with speed and scale. Holistic security features help identify, protect, and remediate against threats and vulnerabilities. The universal, hybrid, multi-cloud JFrog Platform is available as both SaaS services across major cloud service providers and self-hosted. Millions of users and approximately 6,600 organizations worldwide, including a majority of the Fortune 100, depend on JFrog solutions to securely embrace digital transformation in the AI era.