Pudoo
BTC $77,631.8 -3.08%
ETH $2,437.06 -2.92%
SOL $103.52 -4.98%
BNB $689.4 -3.07%
XRP $1.38 -4.92%
DOGE $0.0847 -4.42%
ADA $0.2021 -5.69%
AVAX $7.28 -2.87%
DOT $0.8440 -4.34%
LINK $11.41 -4.22%
⛽ ETH Gas 28 Gwei
Fear&Greed
73

Agent Plugins 1.0 Is Not an Open Market. It's a Common File Format for Walled Gardens.

Projects | CryptoZoe |

The biggest lie in enterprise software is that open standards are neutral. They are not. They are liquidity maps. They tell you where value can flow, which bridges are tolled, and who controls the on-ramp. On August 6, 2026, the agent ecosystem got its npm moment. Agent Plugins 1.0.0 shipped - not as a proposal, not as a white paper, but as a working standard embedded directly into VS Code, GitHub Copilot, Cursor, ChatGPT, and Kiro. Amazon, Microsoft, OpenAI, Vercel, and Cursor adopted it simultaneously. Google joined as a core maintainer the same day. That is historic. It is also a carefully designed liquidity event dressed up in interoperability clothing.

Skepticism isn't about refusing to celebrate a shipped standard. It's about tracing where value accrues the moment the standard runs. So let's trace. The Technical Steering Committee names are public: Clare Liguori from AWS, Roshan Sadanani from Cursor, Harald Kirschner from Microsoft, Gav Verma from OpenAI, and Jonathan Hefner of Vercel as lead core maintainer. The seats belong to individuals, not companies, and the governance charter is designed to prevent any single vendor from holding a majority. The project name, logos, domains, and GitHub organization are held in trust by a neutral entity. That is a genuinely serious governance design. It is also a mask.

Under the hood, Agent Plugins 1.0 packages two building blocks that have been quietly converging for two years. The first is Model Context Protocol, or MCP, which standardizes how AI agents talk to external tools, data sources, and memory systems. The second is Agent Skills, which packages a reusable instruction-and-tool combination into a shareable unit. A plugin wraps an MCP server and its associated agent skills into one portable archive. In principle, a developer can author a plugin once, install it in VS Code, execute it in Cursor, present it to ChatGPT, deploy it in Copilot, and let an autonomous agent in Kiro consume it. On paper, that is interoperability heaven. In practice, it is a shared file format at the bottom of a very tall stack.

Now the timing matters. While the IETF DAWN working group spent July in Vienna wrestling with the discovery layer beneath agent ecosystems, the industry built its own answer. DAWN's charter was deferred at IETF 126 despite twelve pre-charter Internet-Drafts. Agent Plugins 1.0 does not solve discovery; it solves packaging. The difference is not subtle. Packaging is about how capabilities are expressed. Discovery is about how they are found. The coalition chose the layer it could control. If they had waited for DAWN, they would still be in a meeting. Instead, they shipped.

The Economics of the Gatekeeper

Now the part that subscription updates will bury beneath celebratory metrics. The spec deliberately excludes installation mechanisms, distribution protocols, provenance verification, permission models, sandboxing requirements, and marketplaces. Read that list again. Then read it once more. The most commercially valuable layers of any software ecosystem are absent. This is not a gap in engineering. It is a feature of business design. Leave distribution out of the open standard, and each platform operator can build its own channel for how agent skills reach users.

The phrase 'vendor-neutral' is doing enormous work. Open specifications do not create markets; they structure them. The coalition has achieved a rare feat: a shared standard that makes every participant's distribution moat more valuable. In financial markets, that is called a cartel with a customer-friendly veneer. The spec's CC-BY-4.0 license is genuinely open. The economic topology is not.

Google's role is worth a beat. Kevin Hou is leading the effort from the Google Developers side, and Google ships two plugin producers - Agents CLI and Data Agent Kit - but it is not yet listed as a client entry. Translation: Google supports the standard but does not yet control a distribution surface. In an interoperability fight, that is the position of a long-game player. They waited to see where the bundling happens. The client list will change.

Liquidity doesn't flow toward the most open protocol; it flows toward the most effective tollbooth. In ten years of observing crypto markets, I have watched this pattern repeat across every cycle. During the 2017 ICO boom, I audited more than fifty whitepapers and found that the overwhelming majority had no viable liquidity model. They had token supply schedules, verbose roadmaps, and zero path from buyer to seller. In the 2020 DeFi summer, I analyzed the integration of Aave and Uniswap and argued that what looked like a bubble was actually a new permissionless capital efficiency layer. In 2022, I tracked UST withdrawal rates from Terra pool by pool, documenting how a death spiral becomes a liquidation cascade. In 2024, I modeled spot Bitcoin ETF flows against global M2 money supply and watched institutional capital act as a volatility dampener rather than a hype engine. The lesson I keep learning is simple: value accretes to the choke point.

That choke point is now distribution. The specification defines no registry, no marketplace, no discovery endpoint, no revocation mechanism. VS Code will decide which plugins are surfaced to hundreds of millions of developers. Cursor will decide what its power users can install. ChatGPT will decide what its global consumer base can activate. Copilot will decide what an enterprise can deploy. Kiro will decide what appears on its AI-agent timeline. The file format is common. The road network is not. Every platform controls its own on-ramp, its own storefront, its own default installer, and its own revenue share. That is not fragmentation. It is parallel tollbooths with shared signage.

In my pre-analysis days, I launched small utility-token projects in Southeast Asia while auditing token models for a boutique advisory firm. That experience taught me to draw liquidity flow diagrams before reading whitepaper code. The same discipline applies in the agent economy. The moment a developer publishes an agent plugin, that developer is choosing a gatekeeper. If a high-value compliance skill is built, and Microsoft decides to feature a competing skill on the Copilot storefront, the open standard will not save it. Discoverability is the product. The standard only guarantees the package can move. It does not guarantee the package is seen.

For enterprise technology leaders, the cost of switching platforms is now not just technical but commercial. In the old software world, you could move code if you were willing to re-skin the UI. In the agent world, moving from ChatGPT to Cursor may mean rebuilding the entire plugin pipeline, renegotiating support contracts, and re-training your agents on a different discovery experience. The standard does not lower switching costs; it makes them invisible.

I expect a specific objection now. Someone will point out that the spec is CC-BY-4.0, the code is Apache-2.0, Google joined as a core maintainer, and the TSC is structured to be majority-proof. All of that is true. Governance neutrality at the specification layer is not the same as market neutrality at the distribution layer. The founding documents permit any vendor to implement the standard. They do not require any vendor to treat plugins equally. Openness at the packaging layer has never meant openness at the access layer, and anyone who says otherwise has not spent enough time around enterprise procurement.

This is also the moment to revisit the DeFi analogy. For years, VC-backed projects have claimed that liquidity fragmentation is a real problem, and then sold bridges and cross-chain protocols as the cure. My conclusion from the 2020 cycle was the opposite: liquidity fragmentation is not a technological bug; it is a manufactured narrative designed to justify new intermediaries. Agent Plugins 1.0 does not pretend fragmentation is an accident. It leaves distribution proprietary and brands the result a standard. The market will now do what it always does: developers will build on the open layer, scramble to solve distribution, and a new class of discovery intermediaries will emerge to capture the spread. Watch for it.

We can push the macro analogy further. In global markets, a central bank's currency is only valuable if the settlement layer is trusted. Stablecoin issuers learned this in 2022, when unpegged algorithmic stablecoins vaporized billions. A plugin standard is the same: the file format is a promise, but the trust layer is the settlement infrastructure. Version 1.0 ships without a standards-based way to know who wrote a plugin, whether it has been inspected, or what it will do after installation. That is the crypto equivalent of accepting an unaudited smart contract with admin keys. Everyone does it on a testnet. Only fools do it in a bank.

Now the enterprise layer. Version 1.0 contains no provenance or trust model. Per VS Code's own documentation, plugins are implicitly trusted at the moment of installation. There are no cryptographic signatures, no standardized permission model, and no sandboxing requirements written into the spec. For a regulated utility, a public health system, a bank, or any institution with a compliance office, that is a disqualifying condition. You cannot install an unsigned, unsandboxed plugin into a production environment and then tell the risk committee that an npm moment happened. The trust gap is real, and it is structural.

That gap is also a business model. OpenAI Presence launched in July as a governance-focused control plane for enterprise agent behavior. It is designed to sit above the infrastructure layer and decide which agents can do what, with which permissions, under which policy. If Agent Plugins 1.0 succeeds, every serious enterprise will need exactly that control plane on top of a portable plugin format. OpenAI already has a seat at the head of the table. The standard did not threaten OpenAI's moat. It widened it.

MCP gateways are already crystallizing as enterprise infrastructure. The plugin format turns those gateways into traffic controllers. Once MCP becomes the on-ramp for every tool call, the gateway vendor controls observability, policy, and billing. The trust gap in Agent Plugins 1.0 guarantees a layered market: open packaging, proprietary governance. That layering is exactly how enterprise tech has worked for thirty years, and it is how the agent economy will work too.

Anthropic's absence is the most underreported signal. Anthropic authored the Agent Skills specification. It created the .claude-plugin format that informed the standard. Yet Claude Code is not among the launch clients, and no Anthropic representative sits on the Technical Steering Committee. The technical reason is hidden in plain sight: Claude Code's plugin format supports a richer feature set, including custom subagents, hooks, LSP servers, and background monitors. It is also tied to Anthropic's claude.md structure rather than the coalition's agents.md convention. The strategic reason is larger. Anthropic is betting on depth, not breadth; on powerful platform-specific capability, not minimal portable compatibility.

This is the classic two-standards battle, rebuilt for a world of agents. The coalition's plugin format is compact, portable, and predictable. Anthropic's format is heavier, stickier, and more capable. On paper, portable wins because it can run anywhere. In practice, enterprises choose outcomes over interchangeability. If Claude Code's richer format produces better results, fewer hallucinations, stronger policy enforcement, and better internal tooling, then Anthropic can win the enterprise contracts even while losing the format war. The absence from the coalition may be a strategic gift, not a technical rejection.

Now the contrarian read that will be missing from the launch-day press releases. The standard will not fragment the agent economy. It will consolidate it. Think about what simultaneous adoption actually creates. Every major client can load the same plugin, but none of them must share its users. That is not fragmentation. That is a collection of walled gardens with a common file format. The result is closer to an oligopoly that found a shared contract than to an open internet. Each garden keeps its discovery feed, its permissioning, its marketplace, and its revenue share. The file format is the diplomatic passport. The border posts remain firmly closed.

In crypto terms, this is standardizing ERC-20 without standardizing exchanges. The token interface becomes universal, but every exchange still controls listing, custody, and withdrawal. The outcome is never an open token market; the outcome is a set of interoperable monopolies. Agent Plugins 1.0 may become the ERC-20 of the agent era. ERC-20 made token creation effortless and made exchanges vastly richer. Expect the same shape here. The packaging layer will be boring and universally supported. The value will be locked in the distribution and trust layers, inside exactly the companies that signed the standard.

Skepticism isn't a denial of progress; it is a method for locating the next choke point before the market does. Agent Plugins 1.0 will accelerate agent development. I do not doubt that. MCP already proved the demand for standard context plumbing, and the plugin layer will make it more accessible. But acceleration is not the same as decentralization. The governance structure is robust. The market structure is something else. The next eighteen months will be defined not by spec revisions but by distribution defaults.

The immediate test is compatibility under competitive pressure. The TSC was designed to prevent any single vendor from holding a majority, but the real enforcement mechanism is whether VS Code, Cursor, ChatGPT, Copilot, and Kiro treat a plugin written on a rival client as a first-class citizen. Watch whether plugins from one client can be discovered inside another. Watch whether a Cursor-native skill appears in ChatGPT's store. Watch whether Claude Code ever imports the agents.md convention. If not, the standard is a common language, not a common market.

Over a longer arc, the money is in trust. The absence of provenance and permission in version 1.0 guarantees that someone builds the trust layer. OpenAI Presence is the early favorite because it launched in July, just before the standard was adopted. But any platform vendor can build a control plane. The question is which one gets bundled into the enterprise default install. That outcome will not be determined by the open standard. It will be determined by procurement negotiations, enterprise landing pages, and three-year agreements - the same mechanics that built cloud market share and left open-source projects administrating the plumbing.

The closest precedent is containerization. Kubernetes won the orchestration war despite brutal competition from Docker Swarm and Mesos. But the real winners were the managed Kubernetes platforms - EKS, GKE, AKS - and the cloud control planes around them. The open standard created portability at the developer interface and concentration at the operational layer. Agent Plugins 1.0 will follow the same path. The plugin format will be an unremarkable convention. The distribution layer will be a commercially contested battleground.

Liquidity doesn't respect good intentions; it respects settlement layers. In the agent economy, settlement happens at the moment a user installs a plugin. That is the moment of value transfer and the moment of control. The coalition has standardized the package. It has not standardized the market. The question ahead is not whether the standard is open. It is whether the market underneath it is open. After a decade of watching liquidity flow through every kind of on- and off-ramp, I have learned to watch the tollbooths, not the file formats. Agent Plugins 1.0 just gave the agent economy its tollbooths. The only remaining question is who owns the road.

Market Prices

BTC Bitcoin
$77,631.8 -3.08%
ETH Ethereum
$2,437.06 -2.92%
SOL Solana
$103.52 -4.98%
BNB BNB Chain
$689.4 -3.07%
XRP XRP Ledger
$1.38 -4.92%
DOGE Dogecoin
$0.0847 -4.42%
ADA Cardano
$0.2021 -5.69%
AVAX Avalanche
$7.28 -2.87%
DOT Polkadot
$0.8440 -4.34%
LINK Chainlink
$11.41 -4.22%

Fear & Greed

73

Greed

Market Sentiment

Event Calendar

{{年份}}
10
05
upgrade Ethereum Pectra Upgrade

Raises validator limit and account abstraction

12
05
halving BCH Halving

Block reward halving event

08
04
upgrade Solana Firedancer

Independent validator client goes live on mainnet

22
03
unlock Optimism Unlock

Circulating supply increases by about 2%

18
03
unlock Sui Token Unlock

Team and early investor shares released

28
03
unlock Arbitrum Token Unlock

92 million ARB released

30
04
upgrade Celestia Mainnet Upgrade

Improves data availability sampling efficiency

15
04
halving Bitcoin Halving

Block reward reduced to 3.125 BTC

7x24h Flash News

More >
{{快讯列表(10)}} {{loop}}
{{快讯时间}}

{{快讯内容}}

{{快讯标签}}
{{/loop}} {{/快讯列表}}

Tools

All →

Altseason Index

41

Bitcoin Season

BTC Dominance Altseason

Gas Tracker

Ethereum 28 Gwei
BNB Chain 3 Gwei
Polygon 42 Gwei
Arbitrum 0.5 Gwei
Optimism 0.3 Gwei

Market Cap

All →
1
Bitcoin
BTC
$77,631.8
1
Ethereum
ETH
$2,437.06
1
Solana
SOL
$103.52
1
BNB Chain
BNB
$689.4
1
XRP Ledger
XRP
$1.38
1
Dogecoin
DOGE
$0.0847
1
Cardano
ADA
$0.2021
1
Avalanche
AVAX
$7.28
1
Polkadot
DOT
$0.8440
1
Chainlink
LINK
$11.41

🐋 Whale Tracker

🟢
0xd4cd...0c18
30m ago
In
38,982 SOL
🟢
0x9b45...e4b1
30m ago
In
4,965.27 BTC
🔵
0xedce...5046
1h ago
Stake
45,370 SOL

💡 Smart Money

0x7c7e...70f1
Arbitrage Bot
+$1.0M
66%
0x43ed...7527
Top DeFi Miner
+$1.8M
85%
0x0c06...1013
Arbitrage Bot
+$4.5M
89%