Build1 publisher3 min readPublished
Agent Plugins 1.0.0 standardises file paths. Anthropic still owns the behaviour.
Six vendors agreed on where a plugin's components live. The two specifications that define what those components do sit outside the project, and outside its steering committee.
The Engineer · Build desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Vercel released Agent Plugins 1.0.0 earlier this month with core maintainers from AWS, Cursor, Microsoft and OpenAI; Google announced the same day that it was joining them.
- A plugin is a directory containing a plugin.json file at its root; skills go in skills/, with one subdirectory per skill, and MCP servers go in mcp.json.
- Those component locations are fixed, and the manifest cannot move them or declare components inline.
- The plugin manifest requires two fields, $schema and name; everything else is optional metadata.
- Jonathan Hefner, member of technical staff at Vercel, wrote that Agent Plugins gives compatible clients a common format, that the format is intentionally small and easy to implement, and that it leaves installation, distribution, policy, user experience and client-specific capabilities to each client.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
Vercel released Agent Plugins 1.0.0 earlier this month with core maintainers from AWS, Cursor, Microsoft and OpenAI, and Google announced the same day that it was joining them [1]. The format settles where a plugin's files sit and says almost nothing about what those files do, so teams treating it as a portability guarantee are buying a floor.
Mechanically it is small, which is the point. A plugin is a directory with a plugin.json manifest at its root, skills in skills/ with one subdirectory per skill, and MCP servers declared in mcp.json [2]. Those locations are fixed, and the manifest cannot relocate them or declare components inline [3]. The manifest itself requires exactly two fields, $schema and name, with everything else optional [4]. Jonathan Hefner of Vercel, the project's Lead Core Maintainer, wrote that the format is intentionally small and leaves installation, distribution, policy, user experience and client-specific capabilities to each client [5], and that for client implementers it defines a small, deterministic contract for discovery, validation and loading [6].
The delegation is explicit in the text. Section 7.1 names the Agent Skills specification as the source of truth for the SKILL.md format, frontmatter fields and directory layout, leaving Agent Plugins to govern only how skills are discovered inside a plugin, and section 7.2 does the same for MCP wire behaviour and lifecycle [7]. The New Stack notes that a specification could have constrained those contracts by defining a profile, mandating a subset or prohibiting optional features, and that Agent Plugins declines to [8]. Its own documentation calls the result a small interoperability floor, and Google's post describes v1 as a package format and nothing more [9].
Both delegated specifications came out of Anthropic [10]. Anthropic donated MCP to the Agentic AI Foundation, a Linux Foundation-directed fund, on 9 December 2025, and published Agent Skills as an open standard nine days later, now developed in the open at agentskills.io [11], which puts the Agent Skills release on 18 December 2025 [12]. The governance differs: MCP has an independent foundation as steward, Agent Skills does not have a comparable legal one [13]. The Technical Steering Committee is Clare Liguori of Amazon, Roshan Sadanani of Cursor, Harald Kirschner of Microsoft, Gav Verma of OpenAI and Hefner of Vercel [14]. That is zero Anthropic seats out of five [15]. The New Stack reports that no primary source explains the absence [16].
The conformance language shows what "compatible" actually buys. Section 11.1 requires a conformant client to support at least one component type, skills or MCP servers [17], so a skills-only client and an MCP-only client are both conformant while sharing no component support at all [18]. Pavan Madduri, a senior cloud platform engineer at Grainger, told The New Stack the spec "solves the easy problem, not the difficult problem," because a plugin running in six clients is an extra point of failure for permissions, and the specification defers governance, installation policy and permissions management to the client [19]. His formulation: write once, run anywhere becomes compromise once, run everywhere [20].
Two files to watch. The charter names MAINTAINERS as the roster of record, and as of The New Stack's reporting it still lists five people and no Google, despite Google saying it is joining as a Core Maintainer represented by Kevin Hou [21]. The charter also states that governance roles are held by individuals rather than organisations, that no seats are reserved, and that no single vendor may hold a majority of Core Maintainer seats [22], which is worth rereading once the roster changes. The other thing to track is whether Agent Skills acquires a steward with the standing MCP now has [13].