お知らせ • Mar 18
JFrog Ltd Unveils Universal Mcp Registry
JFrog Ltd, the Liquid Software company and creators of the JFrog Software Supply Chain Platform, the system of record for software artifacts, binaries, and AI assets, introduced its JFrog MCP Registry. Expanding on current capabilities in JFrog AI Catalog, the new registry acts as a single source of truth for securely governing Model Context Protocol (MCP) Servers, helping companies transition AI usage from an enterprise-wide compliance and security risk into a competitive advantage. Expanding on current capabilities in JFrog AI Catalog, the new JFrog MCP Registry acts as a single source of truth for securely governing Model Context Protocol (MCP) Servers, helping companies transition AI usage from an enterprise-wide compliance and security risk into a competitive advantage. As AI shifts from simple chat interfaces to autonomous, long-running agents, developers rely on MCP servers to act as "enablers of integration," giving AI models direct access to internal and external enterprise systems, APIs, and data. However, these servers, which act as trusted intermediaries, can also execute arbitrary, potentially malicious code directly on a user's machine or on remote systems with high privileges. If left unmanaged, they expose organizations to severe risks, including prompt hijacking vulnerabilities, over-privileged access, and credential exposure. This need for AI governance is backed by Gartner research1, stating that security and AI leaders must establish MCPs as the foundational method for agents to communicate with external resources by implementing a centralized MCP server registry, enforcing layered security controls, and defining clear ownership and governance policies. The new JFrog MCP Registry provides a system of record and AI infrastructure trust layer for all MCP Servers, agent skills, models, and agentic binary assets. By treating MCP servers with the same rigorous security standards as software packages, the JFrog MCP Registry helps eliminate blind spots across the AI software supply chain. At its core the JFrog MCP Registry is designed to bring: Native security by design to proactively block the download and execution of malicious or non-compliant MCP servers, otherwise pulled naively by humans or AI agents, rather than waiting for an issue to occur and remediating it after the fact. Centralized governance and management enabling developers to instantly access a registry of pre-approved local and remote MCP servers directly from their Integrated Development Environments (e.g., Claude Code, Cursor, VS-Code). Enterprise-grade policy enforcement on every agentic workflow, replacing "blind trust" with granular control, by treating every MCP server as a governed artifact with centralized discovery, configuration and project-level permissions management alongside all other AI models and software artifacts in a unified AI Catalog. Platform universality, which allows companies to seamlessly manage agent ecosystems from private marketplaces and across vendors, enabling teams to seamlessly switch coding agents without ever needing to rebuild their secure system of record. The JFrog MCP Registry is available immediately as part of JFrog AI Catalog.