JFrog AI Catalog Overview
Discover, govern, and secure AI models, MCP servers, and agent assets in the JFrog AI Catalog.
The JFrog AI Catalog is your organization’s hub for discovering, governing, and securing AI assets in the JFrog Platform. From AI/ML > AI Catalog, you manage models, MCP servers, and agent skills in one place—both what your teams already use and what you want to add.
The AI Catalog bridges security teams, platform engineering, and development by giving each team one governed source of truth for AI assets. You browse and evaluate AI assets, decide what each project can use, and enforce policies across the JFrog platform with the same JFrog Curation and JFrog Xray controls you already rely on, so every asset is vetted, secure, and compliant before it reaches production or a coding agent.
How the AI Catalog is Organized
In the JFrog Platform, select AI/ML > AI Catalog. The following table describes the three main areas of the catalog: Marketplace, Registry, and Shadow AI (detection).
| Page | What you do there |
|---|---|
| Marketplace | Explore external AI assets (for example, models and MCP servers) and add them to your catalog. |
| Registry | View and manage the AI assets approved for your organization and projects, and add assets with Add AI asset. |
| Shadow AI | Review AI assets detected in your repositories that are not yet governed, then allow, block, or dismiss them. |
Note:When enabled for your environment, a Feature Store option can also appear for feature sets, features, and data sources.
From Registry and Marketplace you can work across asset types such as models, MCP servers, and skills.
AI Asset Types
The AI Catalog governs several AI asset types across Marketplace and Registry. The following table lists the supported types and their availability.
| AI Asset Types | Description | Availability |
|---|---|---|
| Models: External APIs, package and custom Models |
| Available |
| MCP Servers | Servers that implement the Model Context Protocol and provide governed tools to AI agents. | Available |
| Skills | Versioned bundles of instructions, scripts, and assets that let agents run repeatable tasks under central governance. | Available |
| Plugins | Packaged extensions that add capabilities to coding agents through governed distribution. | Available |
| Agents | Autonomous AI workflows and assistants managed alongside your other AI assets. | Coming soon |
These assets need governance, carry many versions, and can introduce risk, so the AI Catalog manages them in a unified way.
Govern MCP Servers and Skills
The MCP Registry is the system of record for Model Context Protocol servers in the JFrog Platform. You allow servers per project, define tool policies, and scan packages before developers use them. Developers connect coding agents to approved servers through the JFrog Agent Guard, a JFrog CLI plugin that acts as a secure local proxy.
The Skills Registry extends the same project-scoped governance to agent skills. Skills are stored as artifacts, scanned by JFrog Xray, and controlled with policies and waivers, as described in Govern the Skills Registry.
/docs/detect-shadow-ai
Find Unmanaged AI with Shadow AI
Even an empty catalog does not mean your organization is model-free. Shadow AI detection uses JFrog Xray to scan your repositories for AI models that no one centrally approved, then lets you allow, block, or dismiss each one so you can bring existing usage under governance.
AI Catalog supports four main types of AI assets:
These assets need governance, have many versions, and may carry risk. The AI Catalog allows you to manage them in a unified way.
Related Topics:
- JFrog AI Catalog Architecture
- Detect Shadow AI
- AI Catalog Quick Start
- Discover and Allow Models
- MCP Registry Overview
- Get Started with the Skills Registry
- Get Started with the Plugins Registry
Learn more about JFrog AI Catalog at JFrog Academy!
Updated 4 days ago
