APM (Agent Package Manager) is an open source tool that applies familiar package-management concepts to AI agent primitives — skills, prompts, instructions, hooks, commands, and MCP server definitions. By declaring these as versioned dependencies in an `apm.yml` file, teams can ensure every developer uses the same approved agent context across tools like Cursor, Claude Code, and GitHub Copilot. JFrog now supports APM through a new Agent Packages repository type in Artifactory, enabling organizations to publish, version, govern, and audit agent primitives through a trusted internal registry. The integration also extends to GitHub Agentic Workflows, where pinned APM packages can run in CI/CD with human approval gates and AI spend caps. JFrog is also building a security layer to scan APM packages for malicious instructions and unsafe configurations before they reach developers.