<!-- mobian-agent-page publisher="dailydev" canonical="https://daily.dev/posts/the-evolution-of-jfrog-ai-catalog-your-ai-control-plane-for-agentic-development-nndjabi7r" -->

---
title: The Evolution of JFrog AI Catalog: Your AI Control Plane...
description: JFrog AI Catalog has expanded from a secure model registry into a broader AI control plane that governs models, MCP servers, agent skills, plugins, and agent...
canonical: https://daily.dev/posts/the-evolution-of-jfrog-ai-catalog-your-ai-control-plane-for-agentic-development-nndjabi7r
twitter:card: summary_large_image
twitter:site: @dailydotdev
og:type: website
og:site_name: daily.dev
og:title: The Evolution of JFrog AI Catalog: Your AI Control Plane for Agentic Development | daily.dev
og:description: JFrog AI Catalog has expanded from a secure model registry into a broader AI control plane that governs models, MCP servers, agent skills, plugins, and agent...
og:url: https://daily.dev/posts/the-evolution-of-jfrog-ai-catalog-your-ai-control-plane-for-agentic-development-nndjabi7r
og:image: https://api.daily.dev/og/posts/NNDJAbI7r.png
og:image:alt: The Evolution of JFrog AI Catalog: Your AI Control Plane for Agentic Development
og:image:width: 1200
og:image:height: 630
og:locale: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# The Evolution of JFrog AI Catalog: Your AI Control Plane for Agentic Development

**[JFrog](https://daily.dev/sources/jfrog)** · 8 min read · 0 upvotes · 0 comments

## Summary

JFrog AI Catalog has expanded from a secure model registry into a broader AI control plane that governs models, MCP servers, agent skills, plugins, and agent packages as native artifacts inside Artifactory. The post argues that the shift from a human-written SDLC to an agent-driven ADLC opens new attack surfaces, citing real incidents like a malicious Postmark MCP server and the 'omnicogg' malicious skill that evaded VirusTotal detection. New features include semantic scanning (reading asset behavior rather than matching hashes), shadow AI detection, and Agent Guard, which enforces policy at runtime across coding agents like Claude Code, Cursor, and Codex.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://jfrog.com/blog/the-evolution-of-jfrog-ai-catalog>

## Questions this post answers

### What is the omnicogg malicious skill incident and how did it evade detection?

Omnicogg was a malicious AI agent skill that masked a 22MB file containing an encoded payload inside what appeared to be a harmless skill package. It bypassed all 65 VirusTotal scanning engines and accumulated more than 5,000 installs within 19 days before security researchers identified and exposed it.

_Teams vetting agent skills before deployment can follow supply chain security coverage on daily.dev._

### How was the Postmark email MCP server impersonated in a supply chain attack?

A malicious package impersonating the Postmark email MCP server bypassed casual review and ran quietly in the background, silently BCC'ing every email sent through the agent directly to an attacker-controlled address. It illustrates how MCP servers can be weaponized as a covert data exfiltration channel once trusted by an agent.

_Developers wiring MCP servers into coding agents can track emerging MCP threats via daily.dev._

### Why do signature-based security scans fail to catch malicious AI agent skills and MCP servers?

Signature-based scanning only flags files matching known-bad hashes, so a newly created malicious skill or MCP server with no prior hash on record passes through undetected. Catching these requires semantic analysis that reads what an asset instructs an agent to do, rather than just comparing it against previously seen threats.

_Anyone hardening agent pipelines against novel threats can follow AI supply chain security news on daily.dev._

## Similar posts on daily.dev

- [Beyond Models: JFrog AI Catalog Evolves to Detect Shadow AI and Govern MCPs](https://daily.dev/posts/beyond-models-jfrog-ai-catalog-evolves-to-detect-shadow-ai-and-govern-mcps-jsreyq0ej) · JFrog · 0 upvotes · 0 comments
- [How to Secure the Agentic Software Supply Chain with JFrog](https://daily.dev/posts/how-to-secure-the-agentic-software-supply-chain-with-jfrog-w8gjxmtib) · JFrog · 1 upvotes · 0 comments
- [Unlock the Power of Agents with JFrog’s Skills and MCP Tools](https://daily.dev/posts/unlock-the-power-of-agents-with-jfrog-s-skills-and-mcp-tools-ptvhdgpvj) · JFrog · 0 upvotes · 0 comments
- [9 New Innovations. One Trust Layer.](https://daily.dev/posts/9-new-innovations-one-trust-layer--orgvczwlu) · JFrog · 0 upvotes · 0 comments

---

Tags: [#mcp](https://daily.dev/tags/mcp), [#ai-security](https://daily.dev/tags/ai-security), [#jfrog](https://daily.dev/tags/jfrog)

[View this post on daily.dev](https://daily.dev/posts/the-evolution-of-jfrog-ai-catalog-your-ai-control-plane-for-agentic-development-nndjabi7r)

```json
{"@context":"https://schema.org","@graph":[{"@type":"Organization","@id":"https://daily.dev/#organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180},"sameAs":["https://twitter.com/dailydotdev","https://github.com/dailydotdev","https://www.linkedin.com/company/daily-dev-ltd"]},{"@type":"WebSite","@id":"https://daily.dev/#website","url":"https://daily.dev","name":"daily.dev","publisher":{"@id":"https://daily.dev/#organization"},"potentialAction":{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https://daily.dev/search?q={search_term_string}"},"query-input":"required name=search_term_string"}}]}
{"@context":"https://schema.org","@type":"TechArticle","headline":"The Evolution of JFrog AI Catalog: Your AI Control Plane for Agentic Development","url":"https://daily.dev/posts/the-evolution-of-jfrog-ai-catalog-your-ai-control-plane-for-agentic-development-nndjabi7r","mainEntityOfPage":{"@type":"WebPage","@id":"https://daily.dev/posts/the-evolution-of-jfrog-ai-catalog-your-ai-control-plane-for-agentic-development-nndjabi7r"},"datePublished":"2026-09-02T11:59:58.532Z","dateModified":"2026-09-03T15:20:54.778Z","description":"JFrog AI Catalog has expanded from a secure model registry into a broader AI control plane that governs models, MCP servers, agent skills, plugins, and agent...","image":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/17bddfc6ad8b7a427a22cd7ee597c3c6?_a=AQAEuop","thumbnailUrl":"https://media.daily.dev/image/upload/f_auto,q_auto/v1/posts/17bddfc6ad8b7a427a22cd7ee597c3c6?_a=AQAEuop","isAccessibleForFree":true,"articleSection":"JFrog","inLanguage":"en","publisher":{"@type":"Organization","name":"daily.dev","url":"https://daily.dev","logo":{"@type":"ImageObject","url":"https://daily.dev/apple-touch-icon.png","width":180,"height":180}},"author":{"@type":"Organization","name":"JFrog","logo":"https://media.daily.dev/image/upload/t_logo,f_auto/v1/logos/b11bf37102384ac9983be701b2cf7cd5","url":"https://daily.dev/sources/jfrog"},"commentCount":0,"discussionUrl":"https://daily.dev/posts/the-evolution-of-jfrog-ai-catalog-your-ai-control-plane-for-agentic-development-nndjabi7r","interactionStatistic":[{"@type":"InteractionCounter","interactionType":{"@type":"LikeAction"},"userInteractionCount":0},{"@type":"InteractionCounter","interactionType":{"@type":"CommentAction"},"userInteractionCount":0}],"keywords":"mcp,ai-security,jfrog","timeRequired":"PT8M"}
{"@context":"https://schema.org","@type":"BreadcrumbList","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https://daily.dev"},{"@type":"ListItem","position":2,"name":"JFrog","item":"https://daily.dev/sources/jfrog"},{"@type":"ListItem","position":3,"name":"The Evolution of JFrog AI Catalog: Your AI Control Plane for Agentic Development"}]}
{"@context":"https://schema.org","@type":"FAQPage","@id":"https://daily.dev/posts/the-evolution-of-jfrog-ai-catalog-your-ai-control-plane-for-agentic-development-nndjabi7r#faq","mainEntity":[{"@type":"Question","name":"What is the omnicogg malicious skill incident and how did it evade detection?","acceptedAnswer":{"@type":"Answer","text":"Omnicogg was a malicious AI agent skill that masked a 22MB file containing an encoded payload inside what appeared to be a harmless skill package. It bypassed all 65 VirusTotal scanning engines and accumulated more than 5,000 installs within 19 days before security researchers identified and exposed it. Teams vetting agent skills before deployment can follow supply chain security coverage on daily.dev."}},{"@type":"Question","name":"How was the Postmark email MCP server impersonated in a supply chain attack?","acceptedAnswer":{"@type":"Answer","text":"A malicious package impersonating the Postmark email MCP server bypassed casual review and ran quietly in the background, silently BCC'ing every email sent through the agent directly to an attacker-controlled address. It illustrates how MCP servers can be weaponized as a covert data exfiltration channel once trusted by an agent. Developers wiring MCP servers into coding agents can track emerging MCP threats via daily.dev."}},{"@type":"Question","name":"Why do signature-based security scans fail to catch malicious AI agent skills and MCP servers?","acceptedAnswer":{"@type":"Answer","text":"Signature-based scanning only flags files matching known-bad hashes, so a newly created malicious skill or MCP server with no prior hash on record passes through undetected. Catching these requires semantic analysis that reads what an asset instructs an agent to do, rather than just comparing it against previously seen threats. Anyone hardening agent pipelines against novel threats can follow AI supply chain security news on daily.dev."}}]}
```

