JFrog Platform Secures the Agentic Workforce

0
JFrog Ltd. introduced a new set of capabilities designed to secure and govern the agentic workforce. By natively integrating AI assets with the JFrog Platform and enabling an always-on AgentSecOps workflow, JFrog provides a centralized source of truth for every artifact AI agents consume or generate, helping organizations maintain security and policy compliance from initial use through final delivery.

“AI coding agents not only write software at machine speed but also consume software at scale. The DevSecOps controls we built over a decade assumed a human developer was at the keyboard. Today, that assumption has broken – a software supply chain run by agents doesn’t stop for reviews. Agents make decisions about finding and pulling dependencies without a human in the loop, installing traditional packages and AI assets such as skills, context files and MCPs from various sources,” said Yoav Landman, Co-founder and CTO, JFrog. “In order to scale agents responsibly and make sure they are compliant, these dependencies must come from a trusted source. The only way to achieve that is by ingraining an intrinsic immune layer directly into the software supply chain that guarantees every input consumed by agents originates from a single, trusted, secure system of record.”

Why Traditional Security Fails in the Agentic Workforce Era

Gartner’s Hype Cycle for Agentic AI, 2026, states only 17% of organizations have deployed AI agents to date, yet more than 60% expect to do so within the next two years. However, Gartner also predicts that over 40% of agentic AI projects will be canceled by the end of 2027 due to escalating costs, unclear business value, or inadequate risk controls. Recent exploits have demonstrated coding agents are relentlessly task-driven and will bypass safety configurations to complete their task, opening direct pathways for software supply chain attacks.

How to Build a Trusted Agentic Workforce

The new enhancements to the JFrog Platform ensure customers can secure, govern, and control AI agents at scale. New capabilities supporting this AgentSecOps flow include:

Protect What Agents Consume:

  • AI Asset ScanningIndex, scan, and block risky or malicious models, MCPs, skills, and plugins. JFrog performs proactive semantic scanning of markdown files, skills scripts, and instruction sets to block malicious behaviors before they touch a developer’s workstation.
  • Agent Plugins Registry: Governs coding-agent plugins using Agent Guard, ensuring agents across Claude Code, Cursor, VS Code, and more only use vetted, approved plugins.
  • Agent Package Manager (APM) Registry: Integrates the Microsoft-led APM standard into Artifactory, allowing organizations to package, version, and manage AI assets – including prompts, skills, and MCP servers – with full dependency tracking and pinned versions to prevent drift and unvetted sources.
  • Agent GuardNatively enforces project-scoped allow/deny policies from AI Catalog inside developer tools – Claude Code, Cursor, VS Code, and more – so coding agents never bypass organizational guidelines and consume only approved AI assets.

 

Control How Agents Build:

  • JFrog Agent Plugin: Connects agents to your JFrog Platform to bring your organizational standards and policies directly to agent workflows, and completely transparent to developers. Natively integrates across Claude Code, Cursor, Codex, CoPilot, Kiro, and more.
  • Agent Package Resolution: Authenticates and provides a trusted path for agents to resolve package dependencies through JFrog Artifactory, helping ensure agents consume only trusted, verified, audited components governed by your security policies.
  • Network-Layer Protection (Traffic Controller): JFrog Traffic Controller and SASE partners (Cloudflare, Netskope, Zscaler) block public registry calls at the network layer, rerouting all traffic through Artifactory for visibility and control.

 

Enabling Innovation Without Compromising Safety

By centralizing both human-written and agent-generated artifacts in a single, universal system of record, enterprises neutralize vulnerabilities at the point of ingestion (shifting left) without slowing down developer velocity.

“By deploying JFrog, we’ve seen fewer vulnerabilities, which has given our developers more time to focus on building new applications. With all our development teams on one platform, the process is centralized and streamlined,” said Billy Norwood, Chief Information Security Officer at FFF Enterprises. “We’re handling risks further up the chain by shifting left, so vulnerabilities are remediated before anything gets published.”

Learn more about the JFrog Platform and building a trusted agentic workforce by reading JFrog’s latest blog.

Share.

About Author

Taylor Graham, marketing grad with an inner nature to be a perpetual researchist, currently all things IT. Personally and professionally, Taylor is one to know with her tenacity and encouraging spirit. When not working you can find her spending time with friends and family.