Amazon, Microsoft, OpenAI Ship Agent Plugins 1.0 as Industry Sidesteps Standards Debate

On August 6, 2026, a coalition of the most influential platform operators in artificial intelligence shipped Agent Plugins 1.0.0, a vendor-neutral standard for packaging agent capabilities into portable plugins. The group, which includes Amazon (AMZN), Microsoft (MSFT), OpenAI, Vercel and Cursor, did not publish a proposal or circulate a white paper. They shipped working code already integrated into VS Code, GitHub Copilot, Cursor, ChatGPT and Kiro.
The launch landed while the Internet Engineering Task Force's DAWN working group was still debating the discovery layer beneath agent ecosystems. The IETF deferred the DAWN charter at its 126th meeting in Vienna despite 12 pre-charter Internet-Drafts. DAWN stands for Discovery of Agents, Workloads, and Named Entities, and it was seeking working-group status for a decentralized mechanism to let agent components find each other with no pre-configured knowledge of one another. Agent Plugins 1.0 does not solve the same problem. It packages capabilities, not discovery. But the timing is unmistakable. The industry chose shipping over consensus.
Google joined as a core maintainer the same day, with Kevin Hou leading the effort from the Google Developers side. The company ships two plugin producers, its Agents CLI and Data Agent Kit, though it is not yet listed as a client entry. The Technical Steering Committee includes Clare Liguori of AWS, Roshan Sadanani of Cursor, Harald Kirschner of Microsoft, Gav Verma of OpenAI, and Jonathan Hefner of Vercel, who serves as lead core maintainer. The project name, logos, domains and GitHub organization are held in trust by a neutral entity.
| Organization | Role | Representative | Shipping Client |
|---|---|---|---|
| Vercel | Spec author, lead core maintainer | Jonathan Hefner | — |
| Amazon (AWS) | Founding member, TSC seat | Clare Liguori | Kiro |
| Microsoft | Founding member, TSC seat | Harald Kirschner | VS Code, GitHub Copilot |
| OpenAI | Founding member, TSC seat | Gav Verma | ChatGPT |
| Cursor | Founding member, TSC seat | Roshan Sadanani | Cursor |
| Core maintainer, joined launch day | Kevin Hou | Agents CLI, Data Agent Kit |
Note: AAIF's own compatible-clients list also names OpenAI's Codex among the supporting clients, alongside the five above.
The standard builds on two existing technologies: the Model Context Protocol, stewarded by the Linux Foundation's Agentic AI Foundation, and the Agent Skills specification originally created by Anthropic in 2025. Agent Skills holds the instructions for how an agent should perform a specific task. MCP provides connectivity to outside databases, APIs, shell scripts and other external resources. Together, the trio makes AI capabilities modular so that they are, in theory, write-once-run-anywhere.
The technical architecture is deliberately simple. The spec prescribes creating a top-level directory for each plugin, with a small manifest and schema. The manifest provides the name, version and schema in JSON format. Skills are filed in a skills sub-directory, and the MCP server configuration is stored as an mcp.json file. Plugin authors can also use a namespace directory to store additional extensions. This format, according to the Agentic AI Foundation, "keeps the shared format predictable without requiring it to absorb every client-specific experiment happening across agent products."
▲ Agent Plugins only defines the packaging layer (manifest, skills, MCP config). Discovery, installation and marketplaces are left entirely to each client to build on its own.
Vercel posted the initial draft of the spec with input from the coalition partners, all of which pledged fidelity and engineers to the project. The spec is licensed under CC-BY-4.0 for the specification and Apache-2.0 for the code. The Agentic AI Foundation quickly embraced the effort, though Agent Plugins will operate as an independent entity under an open governance model.
The governance charter is designed to prevent any single vendor from holding a majority. Each TSC seat belongs to an individual, not a company. But the real enforcement will be whether competing clients implement the spec in compatible ways.
What Agent Plugins 1.0 deliberately excludes is as significant as what it includes. The standard defines no installation mechanisms, no distribution protocols, no provenance verification, no permission models, no sandboxing requirements and no marketplaces. By leaving distribution out of the standard, the coalition has ensured that each platform operator builds its own channel for how agent skills reach users.
| In Scope (v1.0) | Left to Each Platform |
|---|---|
| Plugin manifest (plugin.json) | Installation and distribution |
| Skills sub-directory | Marketplaces and registries |
| MCP server config (mcp.json) | Permission models |
| Namespace directory for extras | Sandboxing and runtime isolation |
| — | Provenance and cryptographic signing |
This is where the commercial logic becomes clear. The platform operator who ships the client becomes the gatekeeper. Because each platform controls its own distribution, and the spec defines no registry or marketplace, developers who build high-value agent skills are not just building for a standard. They are choosing which gatekeeper controls their access to enterprise buyers and their path to revenue. Each client, VS Code, Cursor, ChatGPT, Copilot and Kiro, will define its own discovery and installation experience. For enterprise technology leaders evaluating agent deployments, the cost of switching platforms is not just technical. It is commercial.
Notably, Anthropic is absent from the coalition, despite having authored the underlying Agent Skills specification and the .claude-plugin format that informed the standard. Claude Code is not among the launch clients, and no Anthropic representative sits on the TSC. Claude Code's plugin format supports a broader feature set, including custom subagents, hooks, LSP servers and background monitors, but it is tied to Anthropic's own client structure using claude.md rather than the agents.md convention the coalition adopted. The absence suggests Anthropic is betting on richer, platform-specific capabilities over the coalition's portable-but-minimal approach. That bet is already visible elsewhere: around the same period, Anthropic shipped a separate plugin system for Cowork, its desktop tool for agentic knowledge work, rather than adopting the coalition's format there either.
The rush to ship also left a significant security gap. Version 1.0 contains no provenance or trust model. Per VS Code documentation, plugins are implicitly trusted at the moment of installation. There are no cryptographic signatures, no standardized permission model and no sandboxing requirements in the spec itself. For enterprise environments where security and compliance are non-negotiable, this is a real hurdle. The trust gap creates demand for governance layers on top of the open standard. OpenAI Presence, which launched in July as a governance-focused control plane for enterprise agent behavior, is positioned to fill exactly this role. As MCP gateways crystallize as enterprise infrastructure, companies will need to layer proprietary control planes on top of the open plugin format to manage risk.
There are other efforts underway to tame the agent development landscape. Google folded its own Agent2Agent agentic communications protocol effort into the Agentic AI Foundation. Google is also building out a specification for finding tools on the web, called Agentic Resource Discovery. The Agentic AI Foundation has a similar project to Agent Plugins, called Skills Over MCP, which shares skills by bundling them into the MCP server itself. AAIF Vice President Angie Jones described that approach as akin to shipping "the manual with the product."
The immediate test for Agent Plugins 1.0 is whether the TSC maintains genuine neutrality or allows platform-specific friction to persist. The coalition has lowered the barrier for building agent skills. Whether the market those skills serve remains open, or becomes a series of walled gardens with a shared file format, is the question that will define the agent economy's next phase.
Once added, BigGo Finance appears first in Google Search Top Stories, so you get the broadest, most up-to-the-minute, and most comprehensive global financial news first.