On August 6, 2026, five of the most consequential distribution companies in software did something unusual: they shipped a standard instead of a marketing plan. Amazon, Microsoft, OpenAI, Vercel, and Cursor simultaneously adopted Agent Plugins 1.0.0 โ an open, vendor-neutral packaging format for Agent Skills and Model Context Protocol (MCP) servers. It is live inside VS Code, GitHub Copilot, Cursor, ChatGPT, and Kiro. Google joined as a core maintainer the same day, with Kevin Hou leading from the Google Developers side. The project name, logos, domains, and GitHub organization sit in a neutral trust.
This is not a proposal. It is not a white paper with aspirational architecture diagrams. It is deployed code running across five of the highest-traffic developer surfaces on Earth, holding the industry's collective attention. But the signal that matters โ the forensic detail that most coverage keeps skipping โ is the specification's deliberate exclusions. Installation. Distribution. Provenance verification. Permission models. Sandboxing requirements. Marketplaces. Six layers, each one absent from the document.
The standard packages the box but refuses to touch the channel. That exclusion is where the real story lives. Strip away the celebratory framing and you find something closer to a land grab wearing a neutral-trust hoodie. And the market has not yet priced the switching costs this creates.
Context: The Consensus Machine Broke Down
To understand why Agent Plugins 1.0.0 matters, you need to see the machinery that failed to produce it. The IETF DAWN working group spent July in Vienna attempting to charter a discovery layer beneath agent ecosystems. Twelve pre-charter Internet-Drafts sat on the table. The proposal aimed to solve how autonomous agents discover each other, how capabilities get routed across the open internet, how identity and delegation are resolved without a central registry.
That charter was deferred at IETF 126. The working group could not reach consensus. And while the IETF debated, the commercial world simply built its own answer.
Agent Plugins 1.0 does not solve the same problem as DAWN. It packages capabilities; it does not discover them. The distinction matters, technically. But the timing is not a coincidence. The industry chose shipping over consensus. That is not a failure of the IETF process โ it is the market announcing where value actually accrues. Not at the protocol table. At the client surface.
Let me be precise about the layers here. Model Context Protocol, originally introduced by Anthropic, standardizes how LLMs connect to external data and tools. Agent Skills is a related layer that defines how a capability gets packaged for execution. The coalition took these concepts and wrapped them into a portable plugin format: a manifest file, a conventional directory structure, and a set of interoperability rules that any compliant client can parse. The result is a file format that travels. That is all it is.
And that is precisely the problem. The format is the least valuable layer of the stack, and it is the only layer these five commercial giants have agreed to standardize. Everything valuable โ installation, trust, distribution, monetization โ was left outside the document.
Anatomy of Intentional Omission
Let's read the spec the way an auditor reads a term sheet. The manifest follows the agents.md convention. The directory structure defines skills and MCP server references. The specification is licensed under CC-BY-4.0. The code is Apache-2.0. About as open as licensing gets.
The Technical Steering Committee includes Clare Liguori (AWS), Roshan Sadanani (Cursor), Harald Kirschner (Microsoft), Gav Verma (OpenAI), and Jonathan Hefner of Vercel as lead core maintainer. Each seat belongs to an individual, not a company. The governance charter prevents any single vendor from holding a majority. On paper, it is textbook neutrality.
But governance design solves for one failure mode while ignoring another. A hostile capture of the package format is unlikely. What is far more probable โ and already observable โ is slow divergence in implementation. Each client parses the same manifest and then presents it through a completely different discovery interface. VS Code has its own plugin browsing experience. Cursor has its own installation flow. ChatGPT has its own marketplace logic. The specification guarantees a common manifest format. It does not guarantee a common user experience, a common permission model, or a common trust boundary.
Based on my audit experience with protocol implementations, this is exactly how "open standards" become effectively proprietary. The file format is open. The implementation surfaces are not. And since the spec excludes distribution by design, the implementation surfaces are where users, developers, and enterprise buyers live.
This pattern is familiar. The early web had open HTML and proprietary browsers. Docker had an open container format and a commercial registry. NPM is open source with a corporate-owned registry at its core. In every case, the packaging layer became the commodity, and the distribution layer became the moat. Agent Plugins 1.0 simply encodes that lesson before the market learns it the hard way.
Gatekeeper Economics: Where the Money Actually Lands
Now we arrive at the quantitative core of the story. By excluding distribution from the standard, the coalition has ensured that each platform operator builds its own channel for how agent skills reach users. The platform operator who ships the client becomes the gatekeeper. This is not a design flaw. It is the design.
Consider the developer building a high-value agent skill โ say, an enterprise-grade compliance summarization tool or a financial data agent. They can make their plugin portable across all five clients. But they cannot distribute it through all five channels simultaneously without building integration with each operator's discovery and procurement system. In practice, they choose one gatekeeper to access enterprise buyers. With two, if they are ambitious.
Here is the switching-cost math that industry analysts will get wrong. A plugin file is portable. The developer's commercial relationship is not. Ratings, security reviews, promotion tiers, payment processing, enterprise procurement contracts โ none of these travel with the manifest file. The technical migration cost approaches zero. The commercial migration cost approaches the total lifetime value of the developer's distribution relationship with the gatekeeper.
From a trading-strategy standpoint, this is textbook rent extraction. The coalition has de-commoditized the client layer by commoditizing the packaging layer. They have reduced the cost of building agent skills, which increases supply, which increases the value of the scarce resource โ a direct channel to enterprise buyers. The standard manufactures a surplus of portable skills, and the platform operators capture that surplus through control of distribution.
I built trading-signal plugins in a previous chapter of my career. The lesson I learned is consistent: the format is never the business. The channel is the business. NPM made JavaScript packages standard; the npm registry still collects the toll. Docker made containers standard; Docker Hub became the default depot. MCP will make agent capabilities standard; every operator at this table is already building the registry that monetizes them.
Arbitrage isn't a term we usually apply to protocol politics, but that is exactly what we are watching. The coalition has extracted value from the packaging layer while skillfully avoiding any commitment at the distribution layer. The perceived openness is the premium the market is paying. The actual economics remain fully enclosed.
Anthropic's Calculated Absence
Now consider the most conspicuous empty seat. Anthropic is not in the coalition. Not on the Technical Steering Committee. Not among the launch clients. Claude Code is absent from the initial client list.
This is not an oversight. Anthropic authored the underlying Agent Skills specification. The .claude-plugin format directly informed the standard. If any company had the legitimacy to shape the packaging era, it was Anthropic. They walked away.
Claude Code's plugin format supports a broader feature set โ custom subagents, hooks, LSP servers, background monitors โ and is tied to Anthropic's client structure through the claude.md convention rather than the agents.md convention adopted by the coalition. The coalition's design is portable but minimal. Anthropic's approach is richer but effectively proprietary.
This is a strategic fork, not a coordination failure. Anthropic is betting that capability depth beats portability. And in the enterprise segment, where the real money lives, that may be the correct wager. Enterprise buyers do not purchase agent skills because the manifest is elegant. They purchase because the agent delivers the outcome โ with the right data, the right permissions, and the right security posture. Anthropic can deliver that faster with a deeply integrated client than a consensus-driven minimal spec designed to preserve neutrality.
The historical record favors this reading. Platform wars rarely end with the open format defeating the richer proprietary integration. Windows beat the open desktop standards of the 1990s through depth of integration. Salesforce became the enterprise default not because of open APIs but because the product formed a complete system. OpenAI's current government-facing momentum suggests the market values capability density over portability.
Anthropic's absence also signals something about the negotiability of the standard. If Anthropic had joined, the coalition could claim true vendor coverage. It did not. The absence creates an opening: for Anthropic to grow Claude Code's plugin ecosystem into a high-value alternative, or for a future reversal if the market demands unified compliance. Either way, the standard shipped with a structural competitor outside the tent. That is a weakness, not a footnote.
The Trust Gap Is a Business Model
Version 1.0 ships with no provenance model. No trust model. Per VS Code documentation, plugins are implicitly trusted at the moment of installation. There are no cryptographic signatures, no standardized permission model, no sandboxing requirements in the specification. Nothing.
Let me put this in terms that compliance officers will recognize: the industry's core agent infrastructure currently has the security posture of downloading executables from a 1998 website.
The attack scenarios are not hypothetical. A malicious skill can exfiltrate credentials accessible through an MCP connection. A poisoned plugin can return manipulated data to a financial model โ think about an AI agent that reads your treasury data and advises on cash deployment. In a bull market, where teams are sprinting to ship agent workflows, this is exactly the period when operational security debt gets accumulated.
We don't fix security retroactively. Every major supply-chain disaster in software history โ the event-stream incident, the ua-parser-js compromise, the 2024 XZ Utils backdoor โ followed the same pattern: a trusted packaging format without a proactive trust layer. The coalition chose to ship without solving for this. They shipped the happy path and deferred the security question to the enterprise governance layer.
The trust gap creates demand. For enterprise environments where security and compliance are non-negotiable, companies will layer governance controls on top of the open format. OpenAI Presence, launched in July as a governance-focused control plane for enterprise agent behavior, is positioned to fill exactly this role. As MCP gateways crystallize into enterprise infrastructure, the proprietary control plane layered on the open plugin format becomes the actual product.
Notice the sequence. The standard's preview circulates in April. OpenAI ships the governance layer in July. The standard goes 1.0 in August. That is not random timing โ that is market positioning. OpenAI did not merely adopt the standard; they shipped the answer to the standard's most glaring omission. If the trust gap persists, the enterprise revenue accrues to whichever operator provides the compliance layer. The standard's minimalism is not a bug to be fixed. It is the canvas on which the gatekeepers will paint their enterprise products.
Governance Theater: Neutrality on Paper
The Technical Steering Committee is structured to prevent one vendor from gaining a majority. Each seat belongs to an individual, not a company. The name, logos, domains, and GitHub organization are held in trust by a neutral entity. This is meaningful structural care.
But the real test is implementation compatibility, not membership arithmetic. When competing clients interpret the spec with different discovery defaults, different permission prompts, different installation trust dialogs, the standard becomes a shared facade over diverging realities. I have seen this pattern in enterprise Ethereum consortia, in token standard governance, and in every attempt to build neutral technical infrastructure on top of competing commercial interests. The committee structure prevents a formal capture. It does not prevent divergent implementation. The divergence is the strategic game.
Each of the launch clients has its own incentive. Amazon will push Agent Plugins through its enterprise cloud marketplace. Microsoft wants developers to think of VS Code as the canonical agent workstation. OpenAI has the presence of the most prominent model brand. Vercel wants to be the deployment layer for agent-infused web experiences. Cursor is positioning as the independent developer brand. The standard unites them at the packaging layer. Their roadmaps diverge everywhere else.
The governance charter also does not address what happens when a client operator creates a proprietary extension to the spec. Standard history is full of "embrace and extend" strategies, and the agent economy is early enough that the dominant extension could become the de facto API. The TSC's neutrality is a reasonable starting position. It is not a guarantee.
I would add a regulatory lens here. The absence of provenance attribution in the standard collides directly with the emerging regulatory backdrop. Global regulators are moving from principles to technical requirements. The US Executive Order on AI safety created concrete expectations for model testing and supply-chain documentation. The EU AI Act introduces harmonized standards for high-risk AI systems that will inevitably touch agent deployment pipelines. NIST's AI Risk Management Framework asks organizations to track agent behavior through auditable systems. A plugin format with no signature and no provenance cannot satisfy those requirements without an external governance layer. The open standard will be compliant only through the proprietary layers built on top of it.
This sets up a two-tier market. Small teams and start-ups will install agent plugins directly, absorbing the trust risk. Enterprises will buy the trusted distribution channel โ through OpenAI Presence, through enterprise cloud marketplaces, through governance layers sold as security solutions. The standard enables democratized access while the absence of trust features drives the enterprises to the paid layer. That is not just an unintended consequence. It is the economic terminus of the design.
The Strategic Blind Spot
The conventional narrative will read Agent Plugins 1.0 as a victory for openness. I read it differently. The standard legitimizes the walled garden as a structural feature of the post-MCP agent economy. The coalition has created a shared packaging format while cementing proprietary distribution. "Open" at the packaging layer. "Closed" at the distribution layer. The standard does not fight the platform moats. It builds a moat moat โ a common trench that protects each platform's individual castle decisions.
Here is the contrarian angle that most observers will miss: the portability claim, taken seriously, actually exposes the coalition's incentive misalignment. If the standard truly made agent skills completely portable, then no client operator would capture skill-marketplace lock-in. The rational move for these five companies would be to sabotage the standard quietly. They did not. They shipped it. The only coherent explanation is that the portability is a marketing asset, not the operating reality. Each operator expects the other four to fail at implementing the standard in an actually interoperable way.
Another blind spot: the trust gap is severe enough that a competitor could define a trustworthy agent plugin format and attract the enterprise market by default. If a startup or a consortium ships a signed-plugin distribution protocol that plugs into the same agents.md manifest, the gatekeepers' enterprise governance layers become the bridge between the open format and compliance. The battle will shift from the packaging standard to the trust standard. None of the five players has publicly occupied that ground, and OpenAI Presence is a control plane, not a trust protocol. There is a wide open lane โ in the cryptographic sense โ for someone who ships a provenance and permission verification layer beneath or beside Agent Plugins 1.0. The opportunity is real, and the absence of an incumbent is loud.
And Anthropic's absence deserves a longer-term read. The richer .claude-plugin format, with subagents and hooks and LSP support, is a bet on capability density. If the market consolidates around a few high-value, deeply integrated agent platforms, Anthropic wins. If the market fragments into a commodity ecosystem of cheap portable skills, the coalition wins. My instinct from observing open-source governance and trading infrastructure for years is that enterprise value continues to concentrate in depth. The coalition's minimal standard may own the long tail while Anthropic owns the enterprise profit pool โ a parallel to how the web had open HTML but the profit concentrated in a few integrated platforms. The standard's success and Anthropic's success are not mutually exclusive. That is the subtlety everyone will miss.
The Next 90 Days
The next quarter will reveal the real architecture. I am watching four specific indicators. First, whether a competitor to OpenAI Presence ships an open trust or provenance layer for Agent Plugins โ a protocol-level answer to the security gap, not a control-plane product. Second, whether Anthropic opens its richer claude.md format to third-party clients or keeps it exclusive to Claude Code. Third, whether the TSC moves past governance theater and addresses implementation compatibility with a formal conformance test suite. Fourth, whether any of the five launch clients breaks the standard's portability promise by shipping an incompatible internal extension disguised as innovation.
The agents economy is being built simultaneously by protocols and by the players who run the clients. This standard is not a destination. It is a flag planted between two economic eras. The math of patience applied to chaos suggests that within eighteen months, the conversation will shift from "which plugin format" to "which trust layer for the default enterprise channel." The gatekeepers know this. They have already begun building the toll booths. The question is not whether agent skills will be portable โ they will be. The question is whether the market around them stays open enough for the long tail to matter, or whether the shared manifest simply becomes the elegantly formatted entrance to a set of private gardens.
Watch the distribution layer. That is where the next war begins. The standard has already been won and lost at the packaging level; the open economy is decided at the channel. And if the open channel does not emerge, the agent economy becomes exactly what the coalition designed it to be: five gardens, one shared fence, no exit.