Security1 distinct publisher2 min readPublished
Agent Package Resolution, now in preview, binds Claude Code and Cursor to Artifactory. Two of its three enforcement layers still run where the agent does.
The Watch · Security desk
Compiled by The WatchSomething wrong?How this is made
Start with the arithmetic in JFrog's own report. If 2025 closed with more than 171,000 unique malicious npm packages after a 451% rise [4], the year opened from a base of roughly 31,000 [1]. That is the volume the curated repository was built to filter, and the filter only works on traffic that arrives at it.
The three described layers are not equally durable. Session steering hands the agent an Artifactory URL for each governed package type at the start of a session [6], which means the agent has to choose to use it. The `jf setup` binding is stronger: it configures the local package manager per project, survives sessions and tools, and catches the installs nobody typed, including postinstall scripts and `pip install -r requirements.txt` [6][7]. Only the third layer, server-side Curation, sits somewhere the requester cannot negotiate with [6]. JFrog writes that each layer enforces independently and that governance does not rely on agent compliance [10]; by the post's own description, two of the three execute in the client environment [2].
The server-side wall governs what passes through Artifactory [6]. It says nothing about a request that never goes there. The post does not describe blocking direct access to public registries or controlling agent egress [11], and public registries remain the default destination for agent-resolved dependencies across npm, PyPI, Maven, Go, Docker Hub, Helm and NuGet [2]. So the control that matters is routing and credentials, not the manifest. Nobody wrote a manifest: the agent picked the packages from a natural-language prompt [3].
Coverage is an allowlist. The feature ships for Claude Code and Cursor, with more agents promised [1]. Every agent, wrapper and CI runner outside that list keeps the behaviour JFrog describes as default rather than exceptional, with scanning and audit trails never applied [8]. And the fix is described entirely in JFrog parts, Artifactory, Curation and Xray [1][7], which is worth remembering when reading a vendor's account of the gap.
Ranked by verification strength, evidence, and original report placement.
JFrog announced Agent Package Resolution (in preview), a feature of the JFrog Agent Plugin that lets AI coding agents natively resolve packages through JFrog Artifactory; it is available for Claude Code or Cursor now, with more agents said to be coming soon.
By default, dependencies retrieved by AI coding agents are pulled directly from public registries: npm, PyPI, Maven, Go, Docker Hub, Helm and NuGet.
With tools like Cursor and Claude Code, users describe intent in natural language and the agent decides what packages are needed and retrieves them autonomously; a prompt such as building a stamp-collection app can trigger a cascade of dependency downloads without the user naming a single package.
Malicious npm package activity surged 451% in 2025, reaching more than 171,000 unique malicious packages, according to JFrog's Software Supply Chain Security State of the Union 2026 report.
Agent Package Resolution has three layers: session steering, which gives the agent the Artifactory URL for each governed package type at the start of each session; persistent package-manager configuration via a one-time jf setup command that binds the local package manager to an Artifactory repository for a project and persists across sessions and tools; and server-side JFrog Curation enforcement, which governs what is allowed through Artifactory regardless of the other two layers.
Coverage claimed includes direct installs resolving from governed Artifactory repositories, indirect and transitive installs such as postinstall scripts and bulk pulls from pip install -r or npm ci, JFrog Curation policy blocking malicious packages and unapproved licenses at the gate, and JFrog Xray scanning every artifact for known CVEs, license violations and operational risk.
Follow any of these and your For You feed starts watching them — no settings page required.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Detailed but single-source and vendor-authored
The mechanism description is specific and internally consistent (three named layers, jf setup, named agents and package types), which makes the product facts credible as a primary source. But the cluster has one publisher, that publisher sells the product, the efficacy assertions are self-graded, and the two headline threat statistics are either from JFrog's own report or attributed to unnamed researchers.
Preview availability, no usage evidence
The only adoption signal is the preview release itself with two supported agents; the cluster contains no customer deployments, install counts, usage disclosures or GA timeline.
Framing outruns demonstrated enforcement
Positive gap: the post claims the governed path becomes 'the only path' with independent, end-to-end enforcement that does not rely on agent compliance, yet two of the three layers run in the client environment and no control over the agent's egress to public registries is described, so the server-side gate only governs traffic that reaches Artifactory. Add preview status and zero measured effectiveness data and the rhetorical certainty exceeds the demonstrated coverage.
Vendor launch citing its own threat research
The single source is a product announcement by the company whose Artifactory, Curation and Xray products are the prescribed remedy, and the demand-side statistics come from JFrog's own report. Strong commercial incentive to maximize both the perceived size of the gap and the completeness of the fix.
Product facts solid, effectiveness unresolved
High confidence that the feature exists as described and that agent dependency pulls default to public registries; low confidence in the completeness of the enforcement claim, the uncited hallucination statistic, and any real-world adoption, because the cluster offers one vendor source and no measurement.
build
Existence checks are dead: attackers now register the packages your AI invents1 distinct publisher
security
Two Artifactory flaws poisoned metadata, not artifacts, and that was enough to break a shared cache1 distinct publisher
build
Claude Code's new default is a confession: the approval prompt was never a control1 distinct publisher
build
A hallucinated package name was already registered when the engineer went looking1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 25, 2026