Fire
Dev Track
EN

The Open Agent Supply Chain

Agent capabilities are becoming dependencies. Now they need a supply chain.

Presented by

Software ate the world because open package ecosystems made innovation composable. They transformed code from isolated artifacts into reusable building blocks—allowing every developer to build on what came before.

Agents are approaching the same inflection point.

Their capabilities—skills, instructions, personas, hooks, and MCP servers—are becoming executable dependencies. Yet today, they are copied between repositories, trapped inside platforms, and deployed with limited provenance, compatibility guarantees, or evidence of quality.

They need a supply chain.

What does it mean to version a skill whose behavior is probabilistic? How do we scan it for security risks, evaluate its quality, match it to compatible models and harnesses, update its dependencies, and govern its complete transitive closure? Who operates the registries, trust systems, and lifecycle automation this ecosystem will require?

This keynote explores the emerging **Open Agent Supply Chain**: not a single product, but a new ecosystem for packaging, distributing, securing, evaluating, and governing agent capabilities.

Using Agent Package Manager as an open-source reference implementation—and JFrog Artifactory’s native support as evidence of a broader category taking shape—we’ll examine what already works, what remains unsolved, and where developers, platform teams, security researchers, and open-source communities can build next.

Because when agent capabilities become open, trustworthy, and composable, innovation does not merely accelerate—it compounds. And the next breakthrough can come from anyone, anywhere.

Dans le même parcours

See also