Product1 distinct publisher3 min readPublished
The company's swampUP 2026 release reads skills files and instruction sets for malicious behaviour and lets an organisation cut agents off from public registries at the network layer, which turns agent conduct into a procurement question.
The Product Desk · Product desk

Compiled by The Product DeskSomething wrong?How this is made
A coding agent halfway through a refactor decides it needs an MCP server it has never used before. In JFrog's model that fetch is a procurement event, and the swampUP 2026 release [6] puts four refusal points in its path: Curation at the moment of the pull [8], Agent Guard's project-scoped allow list inside the developer's tool [2], Agent Package Manager's authentication of the agent itself [5], and Traffic Controller at the network layer [3]. Four chances to deny one dependency request [14].
The last one changes who has to be in the room. Curation, Agent Guard and APM are registry features a platform team can switch on. Traffic Controller works on the wire, which is why Cloudflare, Netskope and Zscaler appear in the same announcement [4]. The person with authority to change every developer's outbound path on a Tuesday usually does not report to the person who wants agent governance by Friday.
Worth separating what is being sold from what someone will be doing. Sold: zero-touch remediation that hands back a safe binary when a developer asks for a vulnerable one [7], policies-as-code written in plain English by an AI tool, prompt-to-release traceability [9], and a joint view with Google Cloud's Wiz of what is running and where it came from [10]. Done, on Monday, by the platform team at a company where agents already write code: somebody owns the list of approved skills, plugins and MCP servers, and somebody answers the developer whose agent stopped because a file was not on that list. JFrog CTO Yoav Landmann framed the goal as remediation without human intervention and without broken builds [11]. Catalog upkeep is the human intervention the goal rests on.
The scanning claim is the one to push on in a demo. The devops.com account describes semantic scanning of markdown files, skills scripts and instruction sets across models, plugins and MCP servers [1], and says nothing about how a file is judged malicious or how often that judgement holds [13]. A scanner pointed at prose has a different error profile from one pointed at compiled code, and a flagged README produces an argument rather than a fix. The same report notes it is unclear how quickly DevSecOps teams are moving to lock their supply chains at all [12], so this is a product bet, not a settled buying pattern.
Sort the assets your agents touch on two axes: whether the artifact carries instructions the agent will act on, and whether the agent can reach it without passing your proxy. Instruction-bearing and directly reachable is the quadrant this release aims at, and the only one where both the prose scanning and the network block do work. Instruction-bearing but already proxied is catalog labour you can start without a purchase order. Code-only and proxied, you handle today. Code-only and directly reachable is the old supply-chain problem with a faster client.
Before scoping any of it, pick one agent and write down where it got its last three dependencies. If nobody in the room can answer, the scanner is being priced against a surface you cannot yet see.
Ranked by verification strength, evidence, and original report placement.
JFrog's AI Asset Scanning uses semantic scanning of markdown files, skills scripts and instruction sets found in AI models, skills, plugins and Model Context Protocol (MCP) servers, in order to block malicious behaviour.
Agent Guard extends JFrog's Artifactory registry to apply governance policies to plug-ins for AI coding agents, natively enforcing project-scoped allow/deny policies from AI Catalog within developer tools so that coding agents consume only approved AI assets.
JFrog Traffic Controller blocks direct calls to public registries at the network layer and reroutes all package traffic through Artifactory.
Cloudflare, Netskope and Zscaler announced support for JFrog Traffic Controller on the same day as the JFrog announcement.
JFrog added registry support for Agent Package Manager (APM), a dependency manager for AI agents developed by Microsoft; APM authenticates AI agents and then creates a trusted path for them to resolve package dependencies through JFrog Artifactory using verified, audited components.
The capabilities were announced by JFrog at its swampUP 2026 conference.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · September 2, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
Artifact Registry's Connector mode puts Artifactory on the pull path for GKE and Cloud Run1 distinct publisher
invest
Rust's arrayref hijack lasted 86 minutes, and Wiz ties it to North Korea1 distinct publisher
security
AI coding agents route around the repository gate, and JFrog moves the checkpoint to the agent1 distinct publisher
build
Three Russian clusters phish the grant, not the password, and MFA completion changes nothing1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One outlet, standing on the vendor's stage
Everything here — the semantic read of skills files, the network-layer cutoff, the four places an agent request can be refused — comes from a single conference-day write-up in devops.com that relays JFrog's descriptions without testing them. The concrete, checkable facts are strong: the CTO is on record by name and three network vendors are named as supporting Traffic Controller. The efficacy claims are the weak half, because no detection rate or classification method is published for the scanner that is supposed to spot a hostile instruction set.
Partners signed, users unseen
Three network security vendors putting their names to Traffic Controller on day one is real ecosystem weight, and Microsoft's Agent Package Manager resolving through Artifactory is a concrete integration rather than an intention. What is entirely missing is anyone using any of it: no customer, no pilot, no deployment count, and devops.com openly says the rate at which teams are hardening supply chains is unclear.
Immune-system language outruns the proof
Immunize, heal, govern, and a coming tsunami of vulnerabilities is a great deal of vocabulary resting on a feature list nobody outside JFrog has measured. The overstatement is not invention — the products were announced, the partners are named, the architecture genuinely stacks four refusal points. It is the distance between blocking malicious agent behaviour as a design goal and a single published number showing the scanner catches anything.
Announcement-day economics
This is a keynote at the company's own user conference, written up the same afternoon. JFrog sells the registry that every one of the four refusal points funnels through; Cloudflare, Netskope and Zscaler sell the network layer doing the rerouting into it; Microsoft gets its agent package manager adopted; Wiz gets a distribution surface. Nobody quoted stands to lose from the story, and no skeptic, competitor or customer appears in it.
Solid on what was said, blank on what it does
We can be fairly sure what was announced and by whom: the account is detailed, internally consistent and names its executive. Beyond that the floor drops away — efficacy, availability, pricing and uptake are all missing, and with only devops.com reporting there is no second read to confirm that the Cloudflare, Netskope and Zscaler support is engineering rather than a joint press line.