JFrog Delivers Trust Layer for AI-Driven Software with NVIDIA
| 5 min read
JFrog Ltd. (Nasdaq: FROG), the Liquid Software company and creators of the JFrog Software Supply Chain Platform, has announced the launch of the new JFrog Agent Skills Registry — validated through early integration with NVIDIA. The platform provides the governance and verifiable trust layer required for agentic workforces to operate securely at enterprise speed and scale.
The Problem: AI Agents Without a Trust Layer
The rapid evolution of AI has made autonomous agents — which rely on skills — a standard part of the modern software supply chain. However, without a dedicated infrastructure layer to enforce policies, security, and privacy controls, these agents introduce significant enterprise risk. Just as a malicious software package can compromise an application, an unvetted skill can guide an agent to perform harmful actions.
Without a standardized infrastructure, organizations face unprecedented security and compliance exposure — as demonstrated by recent OpenClaw manipulations and breaches. The industry's move toward long-running, autonomous agents makes solving this challenge more urgent than ever.
"To safely deploy autonomous agents at scale, organizations must move beyond blind trust. Working closely with the NVIDIA Enterprise AI Factory team, we are establishing a reliable system of record to store, scan, and govern all agentic binary assets across the software supply chain."
— Gal Marder, Chief Strategy Officer, JFrog
Introducing the JFrog Agent Skills Registry
The new JFrog Agent Skills Registry is purpose-built to support NVIDIA Agent Toolkit, including NVIDIA OpenShell — an open-source runtime for building and deploying safe, autonomous, long-running AI agents. Additionally, JFrog Artifactory will serve as a registry for AI models and agent skills with the NVIDIA AI-Q Blueprint, as part of NVIDIA Agent Toolkit.
JFrog's universal solution delivers a trust layer that addresses three core enterprise needs:
- Enhanced security and governance across all MCPs, agent skills, models, and software packages — using a single source of truth to scan and block those with malicious intent or vulnerabilities.
- Secure adoption and scale of autonomous, long-running agents without increasing risk or compromising compliance.
- Powered agentic workflows and developer innovation across the enterprise — safely, continuously, and without disruption.
"Security and governance are key to deploying AI agents in the enterprise. JFrog's Agent Skills Registry for NVIDIA OpenShell supports security and control for deploying long-running agents to help scale enterprise productivity with powerful new AI tools."
— Pat Lee, Vice President, Enterprise Partnerships, NVIDIA
How the Integration Works
By establishing the JFrog Platform as an integrated, secure registry for NVIDIA AI-Q Blueprint and NVIDIA OpenShell runtime, enterprises will be able to safely operate agents using verified skills, MCP servers, models, and software packages. The two teams worked closely to validate a workflow for the ingestion and management of Artifactory as a skills registry — including support for NVIDIA-developed skills, using NVIDIA cuOpt as the first example of a packaged skill.
This integration gives NVIDIA a single, governed endpoint for distributing verified AI skills across all agent platforms, with a promotion model that enforces increasing security gates from team-level to enterprise-wide use.
What the New Offering Includes
- Certified NVIDIA AI-Q Blueprint: The JFrog Platform is validated for lifecycle management and governance of agent skills.
- Native NVIDIA OpenShell Integration: JFrog Artifactory natively integrates with NVIDIA OpenShell runtime to provide secure, private, and scanned resources.
- Centralized Agent System of Record: The JFrog AI Catalog and Agent Skills Registry act as the central control plane for NVIDIA OpenShell — providing a single source of truth to track, audit, and manage the provenance of agents, NVIDIA NIM, and MCP servers.
- Secure Agents and Behaviors: JFrog AI Catalog automatically scans, verifies, and signs all AI skills upon upload to detect vulnerabilities, malicious payloads, and compliance risks before NVIDIA OpenShell or other agents ever adopt them.
- Policy-Driven Governance and Control: The JFrog Platform allows organizations to set strict approval workflows, ensuring developers and AI agents can only access permitted, verified skills for specific projects and business units. The NVIDIA OpenShell runtime then sandboxes each agent in an isolated, virtual environment, enabling safe execution of code without risk of broader network infection.
Why This Matters for the Enterprise
As AI agents become fundamental to how software is created and operated, the absence of a dedicated governance layer poses a growing risk. This collaboration addresses that gap head-on — establishing a verified, auditable foundation for the agentic AI software supply chain that organizations can trust at scale.
For more on how JFrog and NVIDIA are securing the future of agentic AI, visit the JFrog blog on the Agent Skills Registry or explore the solutions page.
Key Takeaways
- JFrog has launched the Agent Skills Registry — a secure system of record for MCPs, AI models, agent skills, and agentic binary assets.
- The platform is validated through early integration with NVIDIA, supporting NVIDIA OpenShell and the NVIDIA AI-Q Blueprint.
- It provides governance, scanning, and policy-driven controls to prevent unvetted or malicious AI agent skills from entering enterprise workflows.
- NVIDIA cuOpt serves as the first example of a packaged, verified skill distributed through the registry.
- The integration establishes a single governed endpoint for AI skill distribution across all agent platforms at enterprise scale.
