Seven of the most powerful software companies in the world just co-signed a standard that refuses to govern the things that actually matter. Vercel, OpenAI, Microsoft, AWS, GitHub, and Cursor put their names behind Agent Plugins 1.0.0 — a packaging format for AI agent plugins that, by its own scope, governs nothing about installation, permissions, or distribution.
Translate that into the language I speak daily. This is a constitution without citizenship. A securities law without a regulator. A blockchain with a consensus rule but no economic finality.
The chain says interoperability. The order book says panic.
Here is the tension in its purest form. The same companies that are fighting viciously for developer mindshare agreed on a “minimum viable interoperability layer” — a phrase that sounds technical and humble but is actually a confession. They standardized the part that is cheap to coordinate: folder structures, manifest declarations, packaging conventions. They deferred the part that is expensive to govern: who can run what, with whose data, under whose liability.

I have seen this play before. In 2017, while analyzing ERC-20 token standards during the ICO mania, I learned that a standard is never just a technical document. It is a coordination game dressed in engineering clothing. The question is never only whether it works. It is who it empowers, who it corners, and who inherits the edge cases.
Agent Plugins 1.0.0 is a coordination game, and the opening move is more sophisticated than it looks.
The problem this standard addresses is real, which is precisely why the politics are so effective.
Building an AI agent Skill — a bundled set of instructions, tool definitions, and configuration that extends a model's capability — should be a write-once, run-anywhere affair. In practice it is not. A developer who crafts a Skill for Cursor must reorganize directory structures, rewrite configuration, and re-declare MCP service connections just to move the same capability into GitHub Copilot or VS Code.
The incompatibility is not logic. It is packaging. The same functionality, expressed in seven different folder arrangements.
Agent Plugins 1.0.0 standardizes the wrapper. Compatible clients can directly recognize and load a plugin without manual reconfiguration. The probable mechanism, judging from the standard's scope, is a unified manifest file — the npm package.json pattern extended across vendor boundaries. A single declarative document that names the Skill, references MCP endpoints, and describes entry points.
This is not a new runtime. It is not a new model architecture. It is a packaging convention, deliberately calibrated to be the smallest possible thing that solves the most visible pain.
When I began managing digital assets professionally, I kept a spreadsheet of every exchange's withdrawal conventions, every custodian's reconciliation format, and every protocol's governance quirk. That spreadsheet was my real edge, because the market was not trading on infrastructure — it was trading despite infrastructure. The same dynamic governs agent development today. Developers are losing weeks not to building but to reformatting, and anything that compresses that tax will win adoption.
I want to be direct about what that calibration means. The standard is an abstraction over existing private formats. OpenAI, Microsoft, and Cursor already maintain proprietary Skill structures; Agent Plugins 1.0 is the public common subset those companies could agree on without revealing their moats. That is why the v1.0 scope is explicitly limited to Skills and MCP. Commands — the procedural logic of a plugin — remain proprietary. Hooks — the lifecycle integration points — remain proprietary. Installation, permissions, and distribution remain the private terrain of each provider.
The alliance itself is the larger artifact. First-wave compatible clients include ChatGPT, Codex, Cursor, GitHub Copilot, and VS Code. The signatories cover every major AI entry point except one.
Anthropic is missing. Claude is not on the list.
And when the missing company is the author of MCP — the very protocol this standard claims to wrap — its absence is the loudest signal in the room.
Tracing the ghost in the liquidity protocol begins with a simple observation: a standards negotiation is a liquidity event for developer attention, and this one has a precise architecture of control.
There are three layers in any plugin economy. The interface says what a plugin is. The execution says what a plugin does. The trust says who is responsible when a plugin does something wrong.
Agent Plugins 1.0.0 attacks only the first layer. It defines what a plugin looks like — the manifest, the directory structure, the MCP references — and then stops. Execution is routed around the standard through proprietary commands and hooks. Trust is explicitly deferred to the individual client vendors.
That is a strategic choice, and as an engineer I respect it. Ethereum's ERC-20 did the same thing in 2017. It standardized an interface — balanceOf, transfer, approve, transferFrom — and left safe math, reentrancy protection, and access control to every implementation. The result was catastrophic in specific places and revolutionary in aggregate. The interface made a universal liquidity layer possible; the missing governance made the DAO hack almost inevitable.
The lesson was not that ERC-20 was wrong. The lesson was that an interface without governance is scaffolding. It accelerates construction and shifts the cost of failure to the tenants.
Agent Plugins 1.0.0 is scaffolding for the agent economy. It will be judged not by whether it is complete but by whether adoption outpaces the gaps.
Now consider the second layer of the game: the relationship to MCP. The Model Context Protocol is Anthropic's contribution to the agent infrastructure stack. It solves the runtime question — how a model invokes external tools and services. Agent Plugins does not fight MCP. It absorbs it. The standard treats MCP servers as packageable objects inside a plugin manifest, wrapping Anthropic's runtime protocol into Vercel's packaging layer.

This is the outer-package maneuver. The value chain in AI agents runs from model, to protocol, to packaging, to distribution. Anthropic owns the protocol layer. OpenAI and Microsoft own the distribution layer. Vercel, by leading the packaging standard, claims the layer in between — the settlement layer of the entire transaction.
The analogy to digital asset markets is almost too precise. In 2020, I audited Uniswap's automated market maker mechanics to evaluate institutional entry into DeFi. The visible layer — the constant product formula, x*y=k — was trivial; any undergraduate could implement it. The actual value lived in the hidden layer: liquidity depth, oracle relationships, liquidation workflows, MEV resistance. The formula was the interface; the leverage was the infrastructure.
One more observation on arbitrary design decisions, drawn from my years in lending protocols. Aave's interest rate curves and Compound's utilization model were always presented as rigorous responses to supply and demand. They were not. They were parameter choices, set by founding teams, survived by convention, and blessed by adoption. The market accepted them because they were the default, not because they were optimal. The same will be true of Agent Plugins: the manifest structure, the folder conventions, the MCP reference syntax — none of these are engineered truths. They are negotiated settlements that will become law through habit. That does not make them bad. It makes them political.
Any firm can publish a packaging standard. Vercel's real asset is not the technical design; it is the web of signatories — Microsoft, OpenAI, AWS — who have agreed to treat Vercel's convention as the default rule. Developer mindshare is a form of cultural capital, and standards are the mechanism by which that capital becomes blockchain finality: irreversible coordination, hardened by distribution.
This is also where the architecture of digital scarcity comes into view. We assume scarcity is a property of tokens, supply curves, and capped issuance. But the scarcest resources in an agent economy are attention and defaults. Vercel is not minting tokens; it is minting a default. And a default, once absorbed into the workflow of millions of developers, is far harder to withdraw than any token.
Now the commercial logic that most commentators will miss, because I have sat on the institutional side of this table. The signatories did not join because they believe in open standards. Microsoft did not join to be nice to Vercel. OpenAI did not join to subsidize a competitor. They joined because the alternative — one player owning the plugin format outright — was worse than any coordinated compromise.
This is consortium mutualization. It is the same logic that produced SWIFT in banking and the ERC governance squabbles in DeFi. Every participant surrenders the ambition of total control to avoid the reality of total subordination. OpenAI receives a richer third-party ecosystem without bearing the cost of maintaining the package format. Microsoft protects GitHub Copilot from isolation in a world where ChatGPT is the default agent client. AWS hedges its exposure across every layer of the stack. The standard is an arms-control treaty, not a peace treaty.
The competitive war does not end. It extends.
Because here is what the announcement does not say. Commands remain the differentiation battleground. Hooks remain the differentiation battleground. Permissions and distribution remain the differentiation battleground. Every vendor will happily share the same folder structure, because folder structures do not make money. None of them will share the user relationship, the policy decision, or the liability absorption.

The standard does not reduce fragmentation. It redefines where fragmentation begins — pushing the differentiation one layer up the stack, exactly where the margins live.
The security problem deserves sharper language than the industry has offered.
A unified packaging format is a malware amplifier. Before this standard, a malicious agent plugin had to be crafted for a single client's quirks and directory conventions — real friction that raised the cost of an attack. After this standard, a single well-formed package deploys across ChatGPT, Copilot, Cursor, and VS Code with zero reconfiguration. The write-once, run-anywhere promise applies to the attacker's code as much as the legitimate developer's.
And the standard has no answer. No code signing requirement. No hash verification. No permission manifest. No sandbox boundary. These were consciously excluded from v1.0.0 and assigned to the “compatible client” layer. This is the Soulbound Token problem in a new costume. The concept of permanently binding credentials to an identity has been technically feasible for three years, and it has not been adopted because nobody wants their credit history — or their access boundaries — permanently visible and enforceable on-chain. Permission declarations in agent plugins face the same barrier: developers will eagerly declare what their plugin does, but they will resist declaring what it can access, because that declaration becomes a legal artifact in an audit trail.
In 2022, I watched Terra/Luna's algorithmic stablecoin fail not because the mechanism was mathematically unsound but because the governance was structurally absent. A beautiful mechanism without a margin of safety is a prayer. Agent Plugins 1.0.0 is the same genre: a well-designed container with no security boundary, released at a moment when every major AI vendor is trying to be the container.
The conventional read says the standard reduces fragmentation. I contend it does the opposite — it shifts fragmentation upward and makes the fragments more dangerous. When every platform shares the packaging but not the permission model, users face an illusion of uniformity. They will assume a plugin that runs safely in VS Code runs safely in ChatGPT. They will be wrong.
There is also a cost side that nobody is quoting. ZK Rollup operators learned the hard way that proving costs only matter when the network is quiet; during bull-market congestion, everyone waves off the expense, and during the drawdown, the bleeding becomes existential. Standards are similar. Maintainers will be surprised by how expensive it is to keep a multi-vendor specification alive — test suites, version migrations, compatibility matrices, security disclosures. The funding for these activities is not in the announcement.
Watch version 1.1. If the next iteration adds code signing, hash verification, and a permission manifest, this becomes a genuine infrastructure layer with the possibility of settling the agent economy's base protocol. If it adds none of these, it is a plot device: Vercel positions itself as the neutral arbiter of packaging while the real governance stays in private repositories.
In the short term, treat Agent Plugins like a DeFi yield: generous at the interface, expensive when you understand the underlying risk. Code is law, but narrative is leverage; the narrative says interoperability while the code is silent about liability.
Volatility is the price of admission — and so is unresolved trust. The market will move first. Audits will follow. They always do.