Anthropic Claude Code users can now run governed, supply-chain-aware AI coding agents, assisted by JFrog’s trusted, universal, multi-agent platform
JFrog Ltd , the creators of the JFrog Software Supply Chain Platform, the system of record for trusted software artifacts, binaries, and AI assets, unveiled its JFrog Platform plugin for Claude Code, in collaboration with Anthropic. Available immediately to all Claude Code users, the new plugin represents a significant milestone in bringing enterprise-grade software supply chain governance to one of the fastest-growing AI coding agent platforms in the world, reinforcing JFrog’s position as a critical trust layer and system of record for the rapidly expanding AI agent environment.
Also Read: CIO Influence Interview with Hugo Dozois-Caouette, CTO and Co-founder at MaintainX
“AI-enabled innovation can’t be at the expense of security or compliance. Companies need a system of record with visibility into the decisions these agents make – that’s what our integration with Anthropic’s Claude Code provides.” – Yoav Landman, JFrog CTO
The need for agent-specific security has been highlighted by Anthropic, stating, “As agents grow more capable, attack surfaces are constantly shifting. The types of failures we’ve seen are likely to be repeated across industries and labs. We need collective investment in agent-specific security posture, from shared benchmarks and disclosure norms to common identity standards and cross-vendor red-teaming.”
“AI agents are active participants in the software supply chain, making decisions about dependencies, builds, and deployments – but most of them are doing it blind, without any supply chain context. This is often how malicious packages, vulnerabilities, and ungoverned AI assets enter production today, exposing organizations to software supply chain attacks,” said Yoav Landman, Co-Founder and CTO of JFrog. “AI-enabled innovation cannot come at the expense of security or compliance. Enterprises need a universal system of record with real-time control and visibility into the decisions these agents make, that’s what this integration enables.”
Governing the Binaries Surge with Agentic DevSecOps
AI coding agents are driving a surge of binaries, with the JFrog Platform currently managing over 18 billion artifacts, a 136% increase from the previous year1. The new JFrog Platform plugin for Claude Code is designed to help organizations tame unorthodox AI agent behavior by providing developers with governed access to scan, curate, and secure every artifact and dependency their agents consume. It also extends Claude Code with deep, domain-specific JFrog Platform Skills, designed to give developers and their agents the ability to execute platform operations using natural language. Combined with the recently announced JFrog MCP Registry and JFrog Agent Skills Registry, the new plugin is expected to deliver:
- Real-time, Upstream Governance: Governance, package security and license compliance, and provenance validation happen inside the development workflow, not after it. Agents enforce policies as code is written, eliminating the manual handoffs that slow releases and introduce risk.
- MCP and Agent Skills Governance: Ensures agents, developers, and AI users only pull verified, secure, and governed MCP servers and agent skills – blocking rogue access to sensitive internal data and preventing unauthorized actions.
- Accelerated DevOps Workflows: Engineering time is no longer wasted on coding repetitive platform tasks. Repository management, project provisioning, and routine operations are handled by agents through JFrog Platform Skills – so developers stay focused on building, not configuring.
- Strengthened Auditability: When an incident or audit happens, teams need answers in minutes, not days. The JFrog Platform plugin provides end-to-end traceability from source commits to build artifacts, so security teams can respond faster and prove compliance without scrambling.
Why Agent Universality Matters Now
The new plugin reflects how JFrog sees the market for trusted agents evolving: teams will use different AI agents and JFrog’s role is to support those choices while maintaining governance and control. Rather than building one agent at a time, the JFrog Platform provides three layers of agent connectivity that work across any AI coding environment, including:
- JFrog Platform Skills, giving agents deep, domain-specific knowledge around the JFrog Platform, enabling complex operations like vulnerability scanning, curation checks, and provenance verification through simple natural language.
- JFrog MCP Tools, join JFrog Skills in providing standardized access to security, compliance, and artifact data across the JFrog Platform, ensuring consistent governance regardless of which agent initiates the request.
- Additional Agent-Native Plugins Support, starting with Claude Code, alongside Cursor and VS Code Copilot. Collectively, these plugins aim to bring the full JFrog Platform into each agent’s native environment with streamlined deployment and simple authentication.
Together, these layers establish the JFrog Platform as the foundational system of record across multi-agent environments – ensuring that governance, provenance, and security travel with the developer, not with any single tool.
Catch more CIO Insights: What Does “Job-Ready” Really Mean in IT and Cybersecurity?
[To share your insights with us, please write to psen@itechseries.com ]


