Today at swampUP 2026, liquid software creator JFrog Ltd. revealed new enterprise security capabilities. These tools directly safeguard and govern the autonomous agentic workforce. Consequently, the company connects AI assets directly to the main JFrog Platform. It establishes an active AgentSecOps workflow across development operations. Thus, the system becomes a single source of truth for all software artifacts. It ensures full compliance for every component consumed or generated by autonomous agents.
“AI coding agents not only write software at machine speed but also consume software at scale. The DevSecOps controls we built over a decade assumed a human developer was at the keyboard. Today, that assumption has broken – a software supply chain run by agents doesn’t stop for reviews. Agents make decisions about finding and pulling dependencies without a human in the loop, installing traditional packages and AI assets such as skills, context files and MCPs from various sources,” said Yoav Landman, Co-founder and CTO, JFrog. “In order to scale agents responsibly and make sure they are compliant, these dependencies must come from a trusted source. The only way to achieve that is by ingraining an intrinsic immune layer directly into the software supply chain that guarantees every input consumed by agents originates from a single, trusted, secure system of record.”
Why Traditional Security Fails in the Agentic Workforce Era
Gartner’s Hype Cycle report indicates rapid adoption of AI agents across enterprises. Currently, seventeen percent of companies use AI agents in production. However, over 60% plan to deploy within two years. Still, Gartner predicts over forty percent of agent projects will fail by 2027. High costs and poor risk controls cause these frequent project cancellations. Meanwhile, coding agents actively bypass traditional security setups to complete tasks faster. This aggressive behavior creates severe vulnerabilities inside the software supply chain. Therefore, modern enterprises need specialized solutions to control their scaling agentic workforce.
How to Build a Trusted Agentic Workforce
To solve this issue, JFrog introduced enhanced features for total control. First, the company protects what the agentic workforce consumes daily. AI Asset Scanning proactively blocks malicious scripts, skills, and models. Then the Agent Plugins Registry manages tools across IDEs like VS Code and Cursor. Meanwhile, Artifactory goes with Microsoft with the Agent Package Manager Registry. It monitors dependencies and prevents the use of unvetted sources. Agent Guard also enforces project-level policies directly in developer tools.
Second, JFrog governs how the digital agentic workforce builds software. The new JFrog Agent Plugin allows agents to connect to platform security policies directly. Agent Package Resolution also provides verified paths for package dependency resolution. Network layer protections like Traffic Controller reroute public calls into Artifactory. Some of the SASE partners that can facilitate such traffic rerouting include Cloudflare, Netskope, and Zscaler.
Innovation Without Compromising on Security
By consolidating their artifacts into a unified record system, enterprises will be able to detect any threats earlier. At the same time, the developers will maintain a fast pace of production.
“By deploying JFrog, we’ve seen fewer vulnerabilities, which has given our developers more time to focus on building new applications. With all our development teams on one platform, the process is centralized and streamlined,” said Billy Norwood, Chief Information Security Officer at FFF Enterprises. “We’re handling risks further up the chain by shifting left, so vulnerabilities are remediated before anything gets published.”
Consequently, organizations can build a resilient, secure agentic workforce without sacrificing delivery velocity.
For related updates on digital trust and cybersecurity, explore our SOC News.
News Source:Businesswire