I didn’t read the August 6 announcement as a technology milestone. I read it as a market structure event — the moment a multibillion-dollar agent economy quietly chose who gets to be the gatekeeper and who gets to be the product.
Here are the facts, stripped of press-release polish. Amazon, Microsoft, OpenAI, Vercel, and Cursor simultaneously adopted Agent Plugins 1.0.0 — an open, vendor-neutral standard for packaging Agent Skills and Model Context Protocol servers into portable plugins. Google joined as a core maintainer the same day, with Kevin Hou leading the effort from the Google Developers side. The standard is already integrated into VS Code, GitHub Copilot, Cursor, ChatGPT, and Kiro. This is not a proposal. This is not a white paper. It is shipped, working code running inside the five most consequential developer surfaces on the planet.
Every developer surface on that list is a distribution channel with millions of daily users. Every one of those users is about to load third-party code into an AI agent that holds enterprise credentials. The press release frames this moment as a truce. I see a land grab wearing a ceasefire.
I’ve audited enough protocol launches to know that when five competitors smile at the same press release, someone is about to do the math and realize the smile doesn’t reach their eyes. The question nobody asks on launch day is the only one that matters: who extracts the rent? The convenient answer is “nobody — it’s open and vendor-neutral.” The cold, structural answer is written in what the spec deliberately excludes.
What Actually Shipped
Agent Plugins 1.0 packages two things: Agent Skills and MCP servers. Let me translate before we get to the trade.
An Agent Skill is a capability bolted onto an AI agent — a tool, a workflow, a domain routine. Think of it as the executable knowledge of an agent: how to check a contract, how to query a data warehouse, how to escalate a support ticket. An MCP server is the plumbing that lets that agent talk to external systems — the transport layer between the model and the world. The standard wraps both into a portable plugin: a file structure any compliant client can load, configured through the agents.md convention.
If you remember the pre-container era of software, the cleanest analogy is npm for the front-end: a package format plus a culture of reusable modules, promising the same explosion of composability that Node.js unleashed a decade ago. A developer builds a payment-reconciliation skill for an agent once. In a perfect world, that same plugin file runs in VS Code, Cursor, ChatGPT, Kiro, or a dozen other tools. Build once, run everywhere. Portable. Vendor-neutral. Open.
That pitch is seductive. It is also roughly as accurate as the early marketing around ERC-20 tokens — technically true about the file format, dangerously silent about the infrastructure underneath. A token standard did not make tokens decentralized. A plugin standard will not make plugins portable in any economic sense. The format is the beginning, not the end.
The coalition framing matters. These six companies control the largest share of developer tooling, cloud compute, and frontier-model distribution in the Western world. When they collectively adopt a container format for agent capabilities, they are not merely standardizing code. They are defining the default shape of the next software economy. The last time this many powerful players aligned on a single spec, the web won. That precedent is exactly why the exclusions in this spec deserve forensic attention.
There is one dimension that makes agent plugins different from every earlier package format: they do not just run on a user’s machine, they act with a user’s permissions. A plugin loaded into an agent session inherits the credentials, the context, the memory, and the decision-making authority of the host agent. That makes the plugin surface a security surface and an economic surface at the same time. Whoever controls the flow of plugins controls a flow of privileged access — and privileged access, once standardized, becomes the most tradable commodity in enterprise IT.
The Timing and the IETF’s Ghost
The political timing matters more than the technical content.
The industry’s preferred path for this was the IETF, where the DAWN working group — the organization chartered to define the discovery layer beneath agent ecosystems — spent July debating in Vienna. The result: the DAWN charter was deferred at IETF 126 despite 12 pre-charter Internet-Drafts. Twelve drafts. Weeks of protocol deliberation about how agents discover and advertise capabilities. Deferred.
Agent Plugins 1.0 does not solve the same problem. It packages capabilities; it does not provide discovery. A plugin file does not help an agent find another agent, or a service, in an open directory. But the timing is not a coincidence. The industry looked at the IETF’s consensus machinery, watched it grind to a halt, and chose shipping over consensus.
That decision carries a price that only becomes visible in retrospect. Standards bodies move slowly because they are designed to surface conflicts and resolve them publicly. The DAWN delay would have forced participants to answer hard questions about discovery, directory ownership, and gatekeeping before the market locked in. The coalition skipped that stage. The result is a standard optimized for speed, with the underlying conflicts left to be resolved by market power instead of protocol design. In crypto terms, this is a fork that did not bother to stage a debate — the miners simply pooled and moved on.
I treat the DAWN deferral as an early signal, not a footnote. When an institutional consensus layer fails, the market always builds a faster, proprietary answer. That answer is usually controlled by the same entities that funded the failed debate. Agent Plugins is that answer. Discovery is still unresolved — which means the next gatekeeper battle is already scheduled. The unresolved discovery layer is the second land grab. The plugin format tells an agent what a capability is, but not who to trust or how to find it. Those functions will become proprietary search surfaces inside each client — the same play as distribution, wrapped in a different name.
The Arithmetic of Omission
My audit rule is simple: never read a spec for what it promises. Read it for what it excludes. Then ask what economic function the missing text was drafted to protect.
The technical specification of Agent Plugins 1.0 is open and vendor-neutral. The business model is anything but.
Count what the standard deliberately leaves out: installation mechanisms. Distribution protocols. Provenance verification. Permission models. Sandboxing requirements. Marketplaces. A registry.
Run them again, slowly, because each one is a profit center in costume. The install path determines who controls the end user’s first touch with third-party code. The distribution rails determine who controls the flow of plugins from developers to enterprises. Provenance verification determines who vouches for a package — and who gets paid to vouch. Permission models determine who defines allowed behavior inside an agent session. Sandboxing determines who contains the damage when a plugin misbehaves. Marketplaces determine who takes a percentage of every transaction. A registry determines who owns the directory — and in any ecosystem, directory ownership is the quiet equivalent of owning the exchange. Every single one of these functions is a business. All seven are outside the standard.
The spec defines what a plugin looks like. It says nothing about how a plugin reaches a user, who vouches for it, what it is allowed to do, or where the money flows.
This is the most important insight in this piece, so let me put it in bold: By leaving distribution out of the standard, the coalition has ensured that each platform operator builds its own channel for how agent skills reach users. The container is shared. The pipeline is proprietary.
And I want to preempt a tempting misreading: this is not an oversight. Nobody in this coalition forgot how to build a marketplace. These are the companies that invented modern developer marketplaces. Amazon has one. Microsoft has one. OpenAI has one. The omissions are the design. The coalition agreed on everything except the only thing that matters — who captures the economic value of the plugins that flow through their software. A standard that shipped without consensus mechanisms, without distribution, and without trust is not incomplete. It is precise.
The Gatekeeper’s P&L
This is where the money lands. The platform operator who ships the client becomes the gatekeeper. Because each platform controls its own distribution — and the spec defines no registry, no marketplace, no discoverable directory — developers who build high-value agent skills are not building for a standard. They are choosing which gatekeeper controls their access to enterprise buyers and their path to revenue. Every architecture decision a developer makes is, first and foremost, a channel decision.
The fragmentation is structural, not accidental. Each client — VS Code, Cursor, ChatGPT, Copilot, Kiro — will define its own discovery and installation experience. The user experience may look similar on the surface; the economics below the surface will diverge immediately. In one ecosystem, installation may be free and distribution open. In another, installation requires submission to a review process, a revenue share on sales, and compliance with the platform’s own policy layer. Developers will not be building neutral software. They will be building for the channel that gives them the least hostile terms — until that channel tightens, as channels always do.
History gives us the template. Every open app economy began with benevolent revenue shares and ended with a platform tax. The same curve hit iOS developers, NFT royalties, and cloud workloads. The speed of the agent economy will compress that curve into quarters, not decades.
I learned this lesson paying tuition in the mempool. In August 2020, I built a Python script to front-run high-value Uniswap V2 swaps — a research experiment that turned into an unexpected crash course in market structure. For three days that bot was a printing press: 140 transactions in a single block, $85,000 in profit. Then the mechanics caught up. Aggressive gas bidding congested nodes. RPC providers started recognizing my IP. I watched my own edge turn into my own liability, and I understood something that has shaped every trade since: the protocol doesn’t decide who gets paid; the execution layer does. The mempool, the sequencer, the channel — that is where the spread lives.
Agent Plugins is that same lesson, rendered in enterprise software. The Ethereum protocol doesn’t include an MEV extraction mechanism in its core spec. It maintains the fiction of neutrality while extraction happens at the edges. Agent Plugins 1.0 maintains the fiction of neutrality while its member platforms extract value at the distribution edge. The open file format is the shared commodity. The gatekeeper is the one who decides whether a plugin reaches a buyer and takes a cut.
In trading terms, the spec is a settlement layer — and commodity settlement layers never capture margin. The last mile does. Card networks own the last mile in payments. Client platforms will own the last mile in agents. The technical artifact is the bait; the channel is the trap.
Enterprise Switching Costs
The enterprise buyer is where the gatekeeping economics become concrete.
For an enterprise technology leader evaluating agent deployments, the standard does not reduce procurement complexity; it relocates it. A deployment that runs on platform A, and only platform A, creates a switching cost with a dollar sign attached. If you want to move your agents to platform B, you do not simply migrate a config file. You migrate your plugin supply chain, your certified skills, your permission policies, your compliance artifacts, and your vendor relationships. Every layer the standard declines to define becomes a layer the enterprise must buy, bespoke, from a vendor.
The source documentation is explicit about the trust gap: plugins are implicitly trusted at the moment of installation. For a regulated enterprise, that single sentence is disqualifying. A bank cannot install third-party code into an agent environment with production permissions and later claim it maintained a compliant control posture. The vendor will sell the missing control layer as an add-on. The standard created the compliance problem, and the vendor sells the compliance solution. That is not an accident of sequencing; that is the product.
The practical consequence is that early enterprise adoption will cluster around platforms that can produce an end-to-end governance story. The open format gives buyers a false sense of optionality. The governance requirement gives vendors real pricing power. Every CIO who approves an agent deployment this quarter is signing a commercial contract, not a technical one. A $500,000 pilot for an agent-assisted order processing workflow demands answers to questions no standard answers: who signs the plugin, who patches it, who indemnifies the enterprise if it drains a database. The platform that supplies those answers supplies the lock-in. Read the spec’s omissions as a procurement forecast, and the picture becomes clear: the money in the agent economy flows to whoever can show the compliance officer something the spec never shipped.
Governance: The Seats Nobody Bought
The governance structure is cleverer than it looks — and I have looked at a lot of governance theater.

The Technical Steering Committee includes Clare Liguori from AWS, Roshan Sadanani from Cursor, Harald Kirschner from Microsoft, Gav Verma from OpenAI, and Jonathan Hefner of Vercel, who serves as lead core maintainer. The project name, logos, domains, and GitHub organization are held in trust by a neutral entity. Each TSC seat belongs to an individual, not a company. The charter is designed to prevent any single vendor from holding a majority.
Let me give credit where credit is due. This is a better governance structure than most crypto projects I’ve audited. I have seen “decentralized governance” mechanisms that were literal rubber stamps for a founder’s wallet. This structure is more careful. The neutral entity holding the assets, the individual-seat design, the absence of a majority shareholder — these are meaningful protections against the most obvious forms of capture.
The problem is that capture is not the only path to control. Multi-vendor neutral governance is alliance theater until the first competitive pressure appears. The market’s real enforcement mechanism is compatibility — whether competing clients implement the spec in ways that actually interoperate. The TSC can maintain perfect neutrality in the meeting room and still fail if every client quietly optimizes for its own ecosystem. The divergences will be framed as “quality improvements”: better defaults, tighter integration, a smoother installation experience. Developers will call them improvements. Enterprises will call them lock-in. Both will be right.
I learned about “neutral governance” the hard way with exchange reserve attestations in 2022. The statements said “independent,” and the independence turned out to be a PDF. I now default to assuming that governance quality degrades under commercial pressure unless proven otherwise. The TSC will get the same assumption from me.
There is a detail most coverage missed. Google joined as a core maintainer the same day and ships two plugin producers — its Agents CLI and Data Agent Kit — but is not yet listed as a client entry. Parse that carefully. Google wants a seat at the standards table and a producer position in the plugin economy, but it has not committed to distributing other people’s plugins under this standard. It retains optionality on the most important commercial question in the ecosystem: whether to enter the distribution game. That is the behavior of a sophisticated market participant. If I were allocating capital in this ecosystem, I would read it as a signal that client-side distribution is the contested ground.
The real test of the TSC’s neutrality will come within two quarters, when the first substantive disagreement appears. Watch the treatment of incompatible implementations. Watch whether the TSC issues interoperability guidance that offends a member’s commercial interest. In standards, neutrality is not declared at launch. It is proven at the first conflict. I do not expect that proof to be comfortable.
Anthropic’s Absence: The Rich Format Bet
The most interesting commercial signal is the missing name.
Anthropic is absent from the coalition — despite having authored the underlying Agent Skills specification and the .claude-plugin format that informed the standard. Claude Code is not among the launch clients. No Anthropic representative sits on the TSC.
The mainstream take will call this an omission. I read it as a strategic divergence with the shape of a trade.
Claude Code’s plugin format supports a broader feature set — custom subagents, hooks, LSP servers, background monitors. The coalition standardized on the agents.md convention rather than Anthropic’s claude.md configuration structure. That fork is a philosophical split with a commercial payload. The coalition’s bet is portable-but-minimal: a thin standard that any client can adopt without excessive engineering work. Anthropic’s bet is rich-but-platform-specific: a deep feature set that is only fully realizable inside Claude Code’s own ecosystem. These are not the same product with different branding. They are opposite theories of where developer value concentrates.
From a cryptography background, I lean toward the ecosystem bet on a five-year horizon. Minimal standards tend to win the long arc of open-source history — the format that runs everywhere outlasts the format that does more. But from a trading desk, I respect the opposing thesis. Enterprises do not buy portability. Enterprises buy power. They buy integration. They buy “our vendor takes responsibility for the entire stack.” Anthropic’s absence lets the coalition claim vendor neutrality while Anthropic quietly builds a moat around the most feature-rich agent client on the market. Third parties who want Claude Code’s full capability set must route through Anthropic’s rails. That is not a technical limitation; it is a business decision disguised as a file format.
I have seen this exact divergence in the Layer 2 wars. The real difference between the optimistic rollup stacks is not the proof system — it is who convinces more projects to deploy chains first. The standard that accrues real usage wins. The same logic applies here. Agent Plugins 1.0 will win or lose based on how many credible agent skills flow through the coalition’s clients, not on the elegance of its schema. And if enterprise usage concentrates in Claude Code’s richer format despite the coalition’s theoretical portability, the open standard becomes the XML of the agent economy: universally supported, commercially irrelevant.
Anthropic’s calculation is not isolationist. It is a hedge. If the coalition standard thrives, Anthropic can adopt it later as a compatibility layer while preserving its extensions. If it stalls, Anthropic loses nothing. The asymmetry favors waiting. In trading, that position is called long optionality. Most commentators will misread it as weakness.
The Trust Gap
Now the part that scares enterprise architects and excites anyone who reads balance sheets: security.
Version 1.0 contains no provenance model. No trust model. Per VS Code documentation, plugins are implicitly trusted at the moment of installation. There are no cryptographic signatures in the standard. No standardized permission model. No sandboxing requirements.
Read that again, because it is the most glaring omission on the whole list: plugins are implicitly trusted at the moment of installation. An enterprise that installs a third-party agent skill is expected to grant it the permissions of the agent session itself. No signature verification. No containment. No defined boundary between what the plugin claims to do and what it is capable of doing.
I do not need to be a cryptography PhD to recognize a supply chain attack with an engraved invitation. I happen to be one anyway, which means I see the problem in sharper relief. The plugin installation flow resembles the dependency ecosystem catastrophe that already cost the software industry years of pain. The event-stream incident taught me that a trusted package can turn malicious overnight — and the trust model was never more than a social network with a version number. Agent Plugins 1.0 will be loaded into agents possessing real enterprise credentials, and its initial version has no cryptographic provenance at all.
The technical fix is not obscure. Cryptographic signatures are a solved problem. Replay-resistant permission manifests are a solved problem. Sandboxing at the agent boundary is difficult but well-trodden. The standard shipped without any of these because they impose cost and friction on the distribution layer. Every verification requirement raises the barrier for independent plugin developers; every permission constraint reduces the appeal of the agent platform. The coalition’s choice to exclude security is a growth decision. I understand the incentive. I am simply telling you the price of adoption: measured in incidents.
This is where the launch becomes genuinely interesting, because the trust gap creates demand for governance layers on top of the open standard. OpenAI Presence, which launched in July as a governance-focused control plane for enterprise agent behavior, is positioned to fill exactly this role. As MCP gateways crystallize into enterprise infrastructure, companies will need to layer proprietary control planes on top of the open plugin format to manage risk.
Let me draw the geometry plainly. The coalition writes an open standard that deliberately excludes permissions, provenance, and policy enforcement. Then a coalition member ships a proprietary control plane to provide exactly those missing functions. The standard creates a documented gap; the vendor fills the gap with a paid product. The hole in the spec has the exact shape of the product. In 2022, I caught the same pattern in stablecoin reserve disclosures — the “transparency” was a marketing artifact, and the gap was the business. I made 320% on that short because I treated the data gap as a signal rather than an oversight. Data gaps are rarely neutral. In markets and in standards, the gap is where the margin hides.
The Historical Pattern
Every package ecosystem follows the same arc. The format becomes free and open. The distribution channel becomes concentrated and rent-bearing.
npm gave the JavaScript world its standard, then the registry became the bottleneck, and the ecosystem spent a decade arguing about governance and security. Maven Central’s governance is far more valuable than the Maven file format itself — you can fork the format, but you cannot fork the accumulated trust of the Central repository. Homebrew’s bottle distribution is effectively controlled by a small maintainer circle; the format is shared, the rails are not. In each case, the open part became commoditized while the closed part became infrastructure — and infrastructure earns the rent.
The agent economy is about to repeat this entire history in hyperdrive, because AI moves at machine speed. The plugin format will be genuinely shared because no one makes money on the format. The distribution, trust, and governance layers are where the money lives. The open format is the trap. The closed distribution is the market.
I know this pattern from the inside, not just the chart side. In 2023, I spent 60 hours executing over 400 distinct transactions across Arbitrum dApps to qualify for the token airdrop. Manual bridging. Liquidity provision. Swaps. The kind of grind that makes passive investors queasy. The result was $45,000 in tokens, which I sold the same day to cover earlier losses. The lesson: wealth in crypto is not primarily a function of capital allocation; it is a function of sweat equity and distribution timing. Airdrops are not charity; they are distribution design. The agent economy is about to run the same playbook at enterprise scale. Developers writing agent skills will discover that their real labor is not writing code — it is solving the distribution puzzle. And the puzzle is designed so that the platforms own the answer.
The difference this time is the speed of adoption. Plugins are not tokens; they are code that acts. The historical package ecosystem cycles took decades. This one will compress into quarters, because every platform now has an AI copilot selling the upgrade. If you are a developer deciding where to invest your skill-building effort, ask a simple question: which channel will still be paying rent twenty-four months from now? The answer is rarely the best technical spec. It is the channel with the most enterprise procurement leverage.
The Contrarian Case
The mainstream read is easy: the industry’s leaders have united on an open standard; the agent economy has its npm moment; interoperability wins. I think that read is not just incomplete. I think it is dangerously wrong.
The coalition has lowered the barrier for building agent skills and raised the barrier for distributing them profitably. The openness of the packaging layer hides the closedness of the distribution layer. Worse, this fake interoperability is more damaging for developers than no standard at all, because it grants the comfort of portability while the economic reality forces every developer to pick a side.
Here is the mechanism. A developer builds a plugin for VS Code. The plugin is portable — technically loadable in ChatGPT, Kiro, or Cursor. But the developer had to build for VS Code’s channel first: its discovery surfaces, its installation flow, its marketplace terms. The abstract standard delivers nothing by itself. Enterprise procurement will buy through channels it trusts, which means the “portable” plugin is economically anchored to the channel that first distributes it. Portability is technically real and commercially fictional. The gap between technical interoperability and commercial lock-in is the exact space where margin gets extracted. I have made money trading that gap for years, so I can tell you with confidence: it is enormous.
The counter-intuitive corollary is that Anthropic may be the one making the correct commercial move by staying out. Consensus wisdom says Anthropic missed the coalition and will eventually capitulate. I am not so sure. Minimal standards win adoption; rich standards win revenue. The coalition’s format wins the long tail of independent developers. Anthropic’s format wins the high-ticket enterprise deals, because enterprises pay for capability and governance, not file-format portability. The coalition’s clients will burn through the long tail, harvesting plugins into their gateways. Anthropic will watch and wait, then decide whether the standard is a threat or a feeder pipe into its ecosystem.
My January 2024 ETF trade taught me the matching lesson. When the SEC approved spot Bitcoin ETFs, retail bought the narrative that institutional legitimacy lifts all assets. I shorted the ETH/BTC pair instead, because legitimacy is a relative value flow: it drains liquidity from the assets not named in the approval. The same relative logic applies here. The “open standard” narrative will flow to the coalition platforms. The revenue may flow to the platforms enterprises actually need for compliance and capability. These are two different tables, and the traders who treat them as one will lose.
The deepest blind spot is trust. The market will celebrate the standard’s neutrality while enterprises quietly buy governance planes. The spec’s silence on permissions and provenance is not technical debt; it is a deliberate opening for commercial control. If you evaluate this standard the way I evaluate a protocol, you do not ask whether it is open. You ask where the missing state lives. In this standard, the missing state — trust, distribution, identity, policy — lives in each vendor’s proprietary layer. The open consortium is a facade over a private ledger.
Let me test the thesis against my own AI trading bot experience. In mid-2025 I deployed an autonomous agent for sentiment analysis on low-cap tokens. I gave it $50,000 and tight execution permissions. It made $180,000 in two weeks — then a sudden market dump made it misread the context, and it gave back 20% before I killed the position. The lesson was never about the model. It was about the boundary. My bot had permission to act but no verified context to act within. An enterprise agent loading a plugin with permission to use APIs but no verified context about what the plugin will do is the same failure mode at different scale. I trust my manual override. Enterprises will need a governance plane for the same reason I needed a manual override. The hidden variable in this entire launch is that every platform is selling the open standard while also selling the closure that makes it safe.
The rhetorical war has already begun. Claiming “open” while shipping a closed trust layer is a linguistic arbitrage. The market will eventually learn to price the difference between an open file format and an open market. That repricing is the trade of the next two years.
What I’m Watching
Let me close with the operational view, because analysis without a position is just commentary.
Three things are on my watchlist.

The compatibility test. Watch for the first client that ships a proprietary extension disguised as a quality improvement. The spin will be “better developer experience.” The reality will be a divergence that makes cross-client plugin migration more expensive. When that happens, the standard has functionally split. The economics become visible from orbit.
The trust war. Whoever ships the dominant enterprise governance layer — OpenAI Presence, an AWS control plane, or a third-party overlay for MCP gateways — captures a recurring revenue stream structurally protected by the spec’s omissions. The spec’s silence on trust is the loudest investment signal in this launch. I would be watching the procurement decisions of regulated enterprises, not the conference panels, to measure adoption.
Anthropic’s next move. If Claude Code eventually adopts the format while retaining its richer feature layer, the standard consolidates and Anthropic wins the premium lane. If Anthropic never joins, the agent economy stays balkanized at the client layer, and Agent Plugins becomes another open standard that solved the wrong problem.
For the enterprise reader, the actionable test is blunt. Ask your vendor three questions: does a plugin verify its signature, which permission model governs plugin execution, and can you migrate a certified plugin portfolio to a competing client without renegotiating commercial terms? If the vendor cannot answer at least two of those, you are not buying a standard. You are buying a landlord.
The standard is licensed under CC-BY-4.0 for the spec and Apache-2.0 for the code. That is about as open as legal layers get. But openness at the packaging layer does not mean openness at the distribution layer. The coalition has lowered the barrier for building agent skills. Whether the market those skills serve remains open — or becomes a series of walled gardens with a shared file format — is the question that will define the agent economy’s next phase.
I don’t trade white papers. I trade distribution. The blockchain doesn’t grant anyone a fair market, and neither will the agent economy. Front-running is not a crime in crypto; it is a structural feature of open systems with closed channels. The agents are about to find out.
Don’t buy the hopium that this standard equalizes power. It doesn’t. It standardizes the container and privatizes the rails. In a bull market for agents, that is the most dangerous asymmetry on the board.