JFrog AI Catalog
by JFrog
Govern the models, MCP servers, skills and plugins your AI coding agents consume
JFrog AI Catalog is the AI governance layer of the JFrog Platform that registers, scans and enforces policy on AI models, MCP servers, agent skills and plugins before coding agents or applications use them. It is built for platform engineering and AppSec teams securing agentic development on Artifactory.
JFrog AI Catalog is the AI governance and security layer of the JFrog Platform, from the Nasdaq-listed software supply chain company founded in 2008 that builds Artifactory. It launched at swampUP 2025 in September 2025 as a secure model registry and has since grown into what JFrog calls an AI control plane that treats models, MCP servers, agent skills, coding-agent plugins and agent packages as first-class artifacts alongside ordinary binaries. The catalog adds a Model Registry, MCP Registry, Agent Skills Registry, Agent Plugins Registry and an Agent Package Manager registry built on the Microsoft-led APM standard, with policy and security scanning applied through JFrog Xray and curation gates that block risky assets before they enter the supply chain. At swampUP 2026, announced September 2-3, 2026, JFrog added Agent Guard, which routes coding agents such as Claude Code, Cursor, GitHub Copilot, OpenAI Codex, Kiro, Devin and VS Code through an authenticated bridge that enforces project-scoped allow and deny rules; AI Asset Scanning, a semantic scan of markdown, skill scripts and instruction sets for malicious intent; Shadow AI Detection for unapproved models already in repositories; and Traffic Controller, backed by Cloudflare, Netskope and Zscaler, which blocks direct calls to public registries. The same release added Zero-Touch Remediation, AppTrust governance features and a Wiz integration. In June 2026 JFrog and the NanoClaw agent project also shipped an integration that forces agent package installs through vetted JFrog registries. AI Catalog and Agent Guard are included in the Enterprise+ tier and sold as add-ons on lower tiers, on SaaS across AWS, Azure and Google Cloud or self-managed. Independent reviews of the underlying Artifactory platform praise its breadth but flag cost, complexity and a steep learning curve.
A head of platform engineering or AppSec at an enterprise already running JFrog Artifactory that is rolling out Claude Code, Cursor or Copilot to many developers.
Coding agents can only pull approved, scanned models, MCP servers, skills and packages, closing an unmonitored path into the software supply chain.
At a Glance
- Category
- Governance & Security
- Pricing
- Subscription, Usage-based
- Target Market
- CTOs, CISOs, Platform Engineering Leaders, Application Security Teams, DevOps Teams
- Deployment
- Hybrid, Multi-cloud, Self-hosted
- Founded
- 2008
- Customers
- Thousands of JFrog Platform customers (vendor-reported); AI Catalog adoption not disclosed
Key Features
- ✓AI asset registries
Stores models, MCP servers, agent skills, coding-agent plugins and agent packages as versioned artifacts with policy applied on every pull.
- ✓Agent Guard
Routes coding agents like Claude Code, Cursor and Copilot through an authenticated bridge enforcing project-scoped allow and deny policies.
- ✓AI Asset Scanning
Semantically scans markdown, skill scripts and instruction sets to catch malicious behaviour hidden in AI assets before agents run them.
- ✓Shadow AI Detection
Finds unapproved AI models already present in repositories and checks them for vulnerabilities and malicious code.
- ✓Curation gates
Blocks risky or non-compliant models and packages before they enter the organization's software supply chain, rather than after deployment.
- ✓Traffic Controller
Blocks direct calls to public registries at the network layer and reroutes traffic through Artifactory, supported by Cloudflare, Netskope and Zscaler.
- ✓Agent Package Manager support
Integrates Microsoft's APM standard so agent dependencies are packaged, version-pinned and resolved only from approved sources.
Use Cases
- •Securing coding-agent rollouts
Platform teams let thousands of developers use Claude Code or Cursor while Agent Guard restricts plugins and MCP servers to vetted ones.
- •Stopping malicious package installs
Agents that try to install a compromised library receive a policy error and are steered to an approved safe version instead.
- •Shadow AI inventory
Security teams scan existing repositories to surface unapproved models and agent assets, then decide what to approve, remediate or remove.
- •Approved model catalog
Organizations publish a governed list of external API models, Hugging Face models and internal models that each project may consume.
- •Compliance evidence for AI-built software
AppTrust traceability records which prompts, assets and approvals led to a release, supporting audits under CRA and NIST SSDF.
Ideal For
Best For
- ✓Governing which MCP servers, skills and plugins AI coding agents may use per project
- ✓Blocking malicious or vulnerable open-source packages that agents try to install autonomously
- ✓Discovering shadow AI models already sitting in internal repositories
- ✓Existing JFrog Artifactory and Xray customers extending supply chain policy to AI assets
- ✓Regulated software organizations preparing for EU Cyber Resilience Act, NIST SSDF or FedRAMP evidence requirements
Not Ideal For
- ✗Teams not using Artifactory, since the catalog works as part of the JFrog Platform rather than as a standalone product
- ✗Small teams without DevOps staff, as reviewers describe the platform as complex to set up and administer
- ✗Budget-constrained buyers on lower tiers, where AI Catalog and Agent Guard are paid add-ons and consumption-based billing makes costs hard to predict
- ✗Organizations seeking runtime LLM prompt-injection or model-output guardrails, which this supply-chain catalog does not position itself around
Deployment
Market & Ratings
Thousands of JFrog Platform customers (vendor-reported); AI Catalog adoption not disclosed
Market Analysis
Pros
- ✓Extends a widely used artifact and security platform to AI assets instead of adding a separate tool
- ✓Broad agent coverage across Claude Code, Cursor, Copilot, Codex, Kiro and Devin
- ✓Semantic scanning targets instruction-level attacks in skills and markdown that traditional SCA misses
- ✓Available on SaaS across three clouds or self-managed on-premises and hybrid
Cons
- ✗Useful mainly to Artifactory customers; the catalog is a platform layer, not a standalone product
- ✗AI Catalog and Agent Guard are add-ons below Enterprise+, with no published add-on prices
- ✗PeerSpot reviewers of the underlying Artifactory platform (4.1/5, 18 reviews) cite high cost and complexity, a steep learning curve, performance bottlenecks with very large artifact volumes, a dated UI and tedious upgrades
- ✗Launch coverage from DevOps.com noted no analyst validation, and Hacker News shows no practitioner discussion of AI Catalog yet
Pricing
Pro (SaaS)
From $150/mo
- ✓25 GB base consumption
- ✓ML model registry and AI asset repositories
- ✓AI Catalog as add-on
Enterprise X (SaaS)
From $950/mo
- ✓125 GB base consumption
- ✓SSO/SCIM and high availability
- ✓AI Catalog and Agent Guard as add-ons
Enterprise+ (SaaS)
Contact for pricing
- ✓AI Catalog, Agent Guard and AppTrust included
- ✓Advanced Security and Curation included
- ✓Multisite and platform federation
Enterprise X (Self-managed)
From $51,000/yr
- ✓3 servers with high availability
- ✓Advanced Security and Curation
- ✓AI Catalog as add-on
JFrog publishes list prices for the platform but not for the AI Catalog or Agent Guard add-ons. Both are bundled only in the custom-priced Enterprise+ tier; on SaaS Pro ($150/month) AI Catalog is an add-on and Agent Guard is unavailable, and on Enterprise X (from $950/month SaaS or $51,000/year self-managed) both are add-ons. SaaS plans are metered on consumption beyond included storage; competitor CloudRepo notes data transfer, including CI downloads, counts toward that consumption.
Security & Compliance
Sources
This page was written from 10 sources, 6 on domains other than jfrog.com.
- 1.jfrog.com — ai catalogvendor
- 2.jfrog.com — the evolution of jfrog ai catalogvendor
- 3.jfrog.com — jfrog embeds security into the agentic workforcevendor
- 4.jfrog.com — pricingvendor
- 5.docs.jfrog.com — jfrog ai catalog overview
- 6.devops.com — jfrog moves to secure agentic engineering workflows
- 7.securitybrief.co.uk — jfrog launches ai era security tools for software supply
- 8.venturebeat.com — nanoclaw and jfrog launch immune system to block ai agents f
- 9.peerspot.com — jfrog artifactory pros and cons
- 10.cloudrepo.io — jfrog artifactory hidden costs
Stay Ahead of the Curve
Weekly enterprise AI insights for technology leaders. No spam, no vendor pitches—unsubscribe anytime.
SubscribeRelated Products
Alice (formerly ActiveFence)
AI red teaming and real-time guardrails for models, apps and agents, built on a decade of adversarial data
Geordie AI
Discover, govern and cost-account every AI agent running across your enterprise
CrowdStrike Falcon Guardian
AI detection and response that finds shadow AI agents on the endpoint and blocks the unapproved ones
Broadcom AgentMinder
Authorize every AI agent action before it happens, not audit it afterwards