JFrog and Anthropic Launch Claude Code Plugin to Automate AI Governance
The new integration targets the 'governance gap' as AI agents accelerate software production beyond the capacity of manual audits.
JFrog has partnered with Anthropic to launch a Platform plugin for Claude Code, aiming to automate security and compliance for AI-driven software development. The move addresses a growing governance gap as autonomous agents accelerate code production beyond the capacity of manual audits.
The new plugin provides real-time governance, package security, license compliance, and provenance validation directly within the AI workflow. Beyond Claude Code, JFrog is expanding its governance capabilities to support other prominent AI coding agents, including Cursor and VS Code Copilot. To facilitate this integration, JFrog has implemented a three-layer connectivity model consisting of Platform Skills, MCP Tools, and Agent-Native Plugins.
The Surge in AI Artifacts
This initiative comes as the volume of software components explodes. The JFrog Platform now manages over 18 billion artifacts, representing a 136% increase over the previous year. According to JFrog, this spike is driven primarily by the surge in AI-generated binaries.
As "agentic" development becomes mainstream, AI agents often make decisions regarding dependencies and builds without full supply chain context. This lack of visibility can allow malicious packages or unlicensed code to enter production environments rapidly, as traditional security checks cannot keep pace with the speed of AI generation.
Shifting the Attack Surface
By integrating compliance "inside the workflow"—a concept known as AgentSecOps—JFrog aims to ensure security policies are enforced while code is being written rather than as a post-development hurdle. This approach allows enterprises to maintain development velocity while adhering to regulatory requirements such as SBOM (Software Bill of Materials) and DORA.
Yoav Landman, Co-Founder and CTO of JFrog, stated that enterprises require a universal system of record to maintain real-time control and visibility into the decisions made by AI agents, noting that innovation cannot come at the expense of security. Anthropic echoed this sentiment, stating that as agents become more capable, the attack surfaces shift, necessitating collective investment in agent-specific security posture.
The Path to AgentSecOps
JFrog is positioning itself as the central system of record for AI assets, including models, agent skills, and MCP servers. The goal is to create a complete chain of custody from the initial prompt to the final release.
Industry observers will now be watching how other AI agent providers integrate with supply chain governance tools. The primary remaining challenge is whether these automated guardrails can evolve as quickly as the agents they are designed to monitor, particularly as agents gain more autonomy over deployment pipelines.