JFrog AI Supply Chain
Centralize, secure, and govern every AI asset in your software supply chain.
AI agents are transforming how software gets built. Teams are adopting coding assistants and AI agents at record speed, shipping faster than ever. However, agents and their unprecedented speed introduce new risks: agents independently discover skills and MCP servers, invoke external AI services or plugins, generate code and binaries, and make runtime decisions faster than any human review cycle. The curated repositories, scanned dependencies, and strict governance you have spent years building no longer cover what's entering and leaving your SDLC: leaving blind spots of unvetted AI assets, fragmented tooling, and unregulated outbound AI traffic.
The JFrog Platform turns that gap into an advantage. Developers get pre-vetted models, MCP servers, skills, and plugins the moment they need them, while security and platform teams keep everything inside the enterprise guardrails they already trust. By governing both what agents consume and what they build, JFrog makes the safe path the fast path, so your teams adopt AI faster, not slower.
Key Use Cases
- Adopt AI coding assistants safely. Allow developers to use Cursor, Claude Code, VS Code, or other coding agents with JFrog’s security and governance standards running natively inside the IDEs and coding agents.
- Curate a trusted catalog of AI assets (models, MCP servers, skills, plugins, and APM packages). Give teams a single vetted source instead of them pulling models directly from public hubs.
- Eliminate Shadow AI. Detect and block unauthorized models and tools before they are used.
- Control AI assets’ consumption. Enforce policy on every tool and skill call your agents make.
- Secure and trace AI-generated artifacts. Apply the same scanning, signing, and provenance to agent inputs and outputs that you already apply to traditional packages.
How it works
- Store & Manage. Create an organizational single source of truth for all AI models, MCPs, skills, plugins, and packages in dedicated repositories with granular access control.
- Scan & Detect. Every asset is analyzed for malicious payloads, prompt injection, and vulnerabilities before it's available for use.
- Catalog & Discover. Teams find and pull approved models, MCP servers, and skills from a central catalog instead of the open internet.
- Enforce & Block. Policies govern how agents execute - controlling tool calls, outbound traffic, and blocking unauthorized or unvetted components.
Capabilities
Store & Manage
AI agents act as virtual developers inside your SDLC. Both the inputs your agents consume and the outputs they generate are supply chain artifacts, and they need the same scanning, signing, and policy controls you already apply to traditional packages.
-
Skills Repositories: Store versioned, ClawHub-compatible skill packages that give agents structured operational context, API patterns, and guardrails for safe execution.
-
Agent Plugins Repositories: Store your organization's plugins and support native plugin downloads.
-
Agent Packages Repositories: Store complete agent configuration packages - skills, plugins, prompts, and agents - and connect to the Agent Package Manager (APM) CLI.
-
AI Editor Extension Repositories: Store and govern AI editor extensions for your development environment.
-
Scoped Tokens and Permission Targets: Create dedicated, granular access tokens for specific operations, replacing global anonymous access with project-scoped read boundaries.
Scan & Detect
-
Malicious AI Model and MCP Server Detection: Continuously analyze models from public repositories to detect hidden malicious payloads and remote code execution logic through a multi-layered, automated verification system.
-
Skill Scanning: Assess AI agent skill packages at upload time using an LLM-powered internal red team to identify prompt injections, unauthorized data exfiltration, and untrusted execution paths.
-
JFrog SAST: Identify and fix security issues early with a fast, accurate static application security testing solution that traces data flow and minimizes false positives.
-
Shadow AI Detection: Identify and block unvetted or unauthorized AI models and tools before they enter your ecosystem, ensuring every AI component complies with your security policies before it can execute.
Catalog & Discover
-
JFrog AI Catalog: Centralize discovery, governance, and secure deployment of external APIs, model packages, custom models, and MCP servers across your organization.
-
MCP Registry: Manage your Model Context Protocol (MCP) servers as an organizational system of record, applying granular, regex-based tool policies and security scanning before agents access your internal systems.
Enforce & Block
-
Official JFrog Agent Plugin: Equip your coding environments and developer chat interfaces with native JFrog capabilities. With official integrations for Cursor, Claude Code, OpenCode, or VS Code, you get artifact management, extension oversight, Agent Guard connectivity, and shift-left security audits right where you code.
-
JFrog’s Agent Guard: Enforce centralized tool policies on every call your developers' coding agents make, directly through the JFrog agent plugins.
Get started
Follow these steps to set up your system of record for your agents:
- Install the JFrog plugin in your coding environment: Cursor, Claude Code, OpenCode, or VS Code.
- Create an AI asset repository for skills, agent plugins, or packages.
- Enable scanning for skills, models, and MCP servers, so nothing enters your ecosystem unvetted.
- Connect to the JFrog AI Catalog to pull vetted models, MCP servers, and skills.
- Define policies for outbound traffic, tool access, and Shadow AI blocking through JFrog Agent Guard.
Find the tools for your role
AI adoption affects every team differently. Use this table to jump to the features most relevant to you.
| Role | Why this matters | Key features |
|---|---|---|
| DevOps | You own the supply chain infrastructure, policy, and risk. The JFrog Platform extends your existing trust model to AI, closing critical execution blind spots and preventing Shadow AI while keeping developers fast. | |
| Security | You need to accelerate AI adoption without losing control or visibility, keeping the ecosystem secure and compliant. | |
| Developer | You use AI coding assistants daily. You benefit from guardrails that run natively and seamlessly inside your IDE without slowing you down. |
Updated about 1 month ago
