JFrog AI Catalog Overview

Discover, govern, and secure AI models, MCP servers, and agent assets in the JFrog AI Catalog.

The JFrog AI Catalog is your organization’s hub for discovering, governing, and securing AI assets in the JFrog Platform. From AI/ML > AI Catalog, you manage models, MCP servers, and agent skills in one place—both what your teams already use and what you want to add.

The AI Catalog bridges security teams, platform engineering, and development by giving each team one governed source of truth for AI assets. You browse and evaluate AI assets, decide what each project can use, and enforce policies across the JFrog platform with the same JFrog Curation and JFrog Xray controls you already rely on, so every asset is vetted, secure, and compliant before it reaches production or a coding agent.

How the AI Catalog is Organized

In the JFrog Platform, select AI/ML > AI Catalog. The following table describes the three main areas of the catalog: Marketplace, Registry, and Shadow AI (detection).

PageWhat you do there
MarketplaceExplore external AI assets (for example, models and MCP servers) and add them to your catalog.
RegistryView and manage the AI assets approved for your organization and projects, and add assets with Add AI asset.
Shadow AIReview AI assets detected in your repositories that are not yet governed, then allow, block, or dismiss them.
📘

Note:

When enabled for your environment, a Feature Store option can also appear for feature sets, features, and data sources.

From Registry and Marketplace you can work across asset types such as models, MCP servers, and skills.

AI Asset Types

The AI Catalog governs several AI asset types across Marketplace and Registry. The following table lists the supported types and their availability.

AI Asset TypesDescriptionAvailability
Models: External APIs, package and custom Models
  • Models accessed through third-party APIs, for example OpenAI and Google Gemini.
  • Open-source models from public repositories such as Hugging Face.
  • Internally developed models tailored to your organization's needs.
Available
MCP ServersServers that implement the Model Context Protocol and provide governed tools to AI agents.Available
SkillsVersioned bundles of instructions, scripts, and assets that let agents run repeatable tasks under central governance.Available
PluginsPackaged extensions that add capabilities to coding agents through governed distribution.Available
AgentsAutonomous AI workflows and assistants managed alongside your other AI assets.Coming soon

These assets need governance, carry many versions, and can introduce risk, so the AI Catalog manages them in a unified way.

Govern MCP Servers and Skills

The MCP Registry is the system of record for Model Context Protocol servers in the JFrog Platform. You allow servers per project, define tool policies, and scan packages before developers use them. Developers connect coding agents to approved servers through the JFrog Agent Guard, a JFrog CLI plugin that acts as a secure local proxy.

The Skills Registry extends the same project-scoped governance to agent skills. Skills are stored as artifacts, scanned by JFrog Xray, and controlled with policies and waivers, as described in Govern the Skills Registry.

/docs/detect-shadow-ai

Find Unmanaged AI with Shadow AI

Even an empty catalog does not mean your organization is model-free. Shadow AI detection uses JFrog Xray to scan your repositories for AI models that no one centrally approved, then lets you allow, block, or dismiss each one so you can bring existing usage under governance.

AI Catalog supports four main types of AI assets:

These assets need governance, have many versions, and may carry risk. The AI Catalog allows you to manage them in a unified way.

Related Topics:

🐸

Learn more about JFrog AI Catalog at JFrog Academy!


Did this page help you?