Build1 distinct publisher2 min readPublished
Lock-in migrated from the model to the runtime that holds your tool grants, approval rules and learned state. Six specifications aim to make that runtime's contents portable, and half of them are one person's drafts.
The Engineer · Build desk

Compiled by The EngineerSomething wrong?How this is made
The stickiness is in the loop. A harness holds the conversation, dispatches each tool call, checks it against a permission rule, manages context, and turns the model's text into work [1]. Every one of those steps writes state, and the state lands in different places: the system prompt on one screen, the tool grants on another, the context in a proprietary store, the approval rules in what the piece calls a settings page nobody remembers configuring [15]. That last location I believe without needing evidence.
What a specification does here is the trick Parquet did for files, Iceberg for tables and Polaris for catalogs: it turns a proprietary internal structure into a document any conforming system reads [14]. The trick has a boundary. The document carries the rule; the enforcement point stays inside the loop. Two harnesses can parse the same approval artifact and still disagree about which call trips it, because a spec constrains the file and not the runtime reading it. So the useful test for each of the six is a second implementation, preferably an unfriendly one, that reads the artifact and produces the same grants and the same refusals. And a spec is only half a migration path. The other half is the incumbent product choosing to emit the artifact, which no document can compel.
By that test the six are unevenly placed, and the source is explicit that they are not competitors, each answering a different question, with a complete system needing an answer to all six [17]. Three have outside stewards [6]. The other three, OAP, AGS and AAIS, were written by the author, who also works at Dremio, which ships an MCP Server as part of its platform [8]. He states this near the top and tells readers to weigh his enthusiasm accordingly [9], which is the right way to publish a spec you wrote. It still means half the coverage of a six-artifact stack rests on drafts with a single author [16], and the approval artifact is in that half.
Timing is what makes this expensive rather than merely irritating. The piece puts the wall at around month three [10] and dates real usefulness to the gap between day one and day 180 [11]. An agent becomes worth moving on the same curve that makes it hard to move.
Agent Skills is the one the source credits with adoption across directly competing vendors [7]. On the evidence supplied, that is the only artifact type here with any claim to having crossed between two runtimes whose owners have no interest in each other's success.
Ranked by verification strength, evidence, and original report placement.
The article defines a harness as the runtime around a model: the software that holds the conversation loop, executes tool calls, enforces permissions, manages context, and turns a model's text output into actual work.
The article names Claude Code, OpenAI's Codex CLI, Cursor's agent mode, Goose, OpenCode and internal orchestrators enterprises build on frameworks as harnesses, and calls the harness the layer that quietly inherited the lock-in previously argued over at the storage/table-format and model layers.
The article lists what accumulates inside a harness after six months of real use: agent definitions (roles, instructions, personas), tool connections, procedural knowledge, work plans, approval rules, and learned state.
The article walks through six specifications it says together make the pieces of an agentic system portable: the Model Context Protocol (MCP), Agent Skills, Agent2Agent (A2A), the Open Agent Profile (OAP), the Agentic Graph Specification (AGS), and the Agent Approval Interchange Specification (AAIS).
The article says three of the six have institutional weight behind them: MCP and A2A both live at the Linux Foundation, and Agent Skills is stewarded through the Agentic AI Foundation.
The author discloses that he authored the last three of the six specifications (OAP, AGS and AAIS) and that he works at Dremio, which ships an MCP Server as part of its platform.
Distinct publishers with included, body-backed reporting in this cluster.
dev.to
1 article · August 31, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
build
Agent Plugins 1.0.0 standardises file paths. Anthropic still owns the behaviour.1 distinct publisher
build
Superpowers makes spec-driven work a precondition, then ships it to twelve harnesses1 distinct publisher
product
Agent protocols now share one landlord: A2A joins MCP and AGENTS.md at the Linux Foundation1 distinct publisher
build
Three named agents shipped in 27 days, and none of them can read each other's config1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One voice, two grades of claim
The checkable parts check out: MCP's release, its move under Linux Foundation governance, Iceberg turning tables into a document any engine can read. The parts doing the persuading do not come with receipts — the month-three wall, the teams that never migrate, the competing vendors said to have adopted Agent Skills. Everything, verifiable or not, arrives through the same dev.to post by the same author.
Three shipping, three on paper
Adoption splits down the middle of the recommended stack. MCP has a release date, a governance home and at least one platform shipping a server — the author's employer's. For OAP, AGS and AAIS this reporting produces no user, no implementing runtime and no harness that reads them; the author's own defence is that the gaps they name will outlive the documents.
Framing outruns the drafts
The promise is that six specifications decide whether an agent can move; three of them are one man's unimplemented drafts, and he says so in his fourth paragraph rather than burying it. That candour is why this reads as overreach in the headline rather than a sales pitch in disguise — the taxonomy is stronger than the six documents it is hung on.
Author of half of what he recommends
Two interests point the same way here: the author wrote OAP, AGS and AAIS, and he draws a salary from Dremio, whose platform ships an MCP Server. Open specifications are good for a data vendor selling engine-agnostic access, and adopted specifications are good for the person who drafted them. Both are stated plainly in the text, which is disclosure, not neutralisation.
Trust the taxonomy, not the tally
We would stake something on the structural argument: lock-in has migrated to the runtime, and the six artifact types are the right things to ask about. We would stake much less on the specific six-document answer, on the month-three timing, or on any adoption figure, since one interested author is the entire evidentiary base and no other publisher has touched it.