# Agent Plugins Explained: The plugin.json Packaging Standard

> How the Agent Plugins Specification v1.0.0 packages Agent Skills and MCP server configs into one portable, plugin.json-manifested directory — the manifest fields, the two component types, and who governs the spec.

Category: Reference · Updated: 2026-08-21 · Tags: agent-plugins, plugin-json, standard, agent-skills, mcp, packaging, agents
Canonical: https://changegamer.ai/resources/agent-plugins-explained
Variants: [HTML](https://changegamer.ai/resources/agent-plugins-explained) · [JSON](https://changegamer.ai/api/resources/agent-plugins-explained.json)
License: https://changegamer.ai/license.xml · Access: free

The Agent Plugins Specification is an open, vendor-neutral packaging standard that bundles Agent Skills and MCP server configurations into a single, portable directory, described by a `plugin.json` manifest at its root. Version 1.0.0 is the current published spec; multiple outlets place its announcement around August 6, 2026 (see Verified sources for that caveat).

## Key facts

- `plugin.json` requires exactly two fields: `$schema` and `name`. Optional fields are `version`, `description`, `author`, `homepage`, `repository`, `license`, `keywords`, and `extensions`.
- A plugin bundles exactly two component types: **skills** — one or more `skills/<name>/` directories, each containing a `SKILL.md` per the separate Agent Skills specification (see /resources/agent-skills-explained) — and **MCP servers** — declared in an `mcp.json` file, supporting `stdio`, `streamable-http`, and `sse` transports (see /resources/mcp-primitives).
- An optional, advanced feature lets a plugin ship client-specific behavior in reverse-domain-named directories (e.g. `{namespace}/`), for host-specific extensions outside the two core component types.
- The spec text is published in the `agent-plugins-spec` GitHub repository, alongside sibling repos `agent-plugins-site` and `agent-plugins-example`, and its own `GOVERNANCE.md`.

## Governance

- Maintained by five named Core Maintainers, each affiliated with a different major agent-tooling vendor: Clare Liguori (Amazon), Roshan Sadanani (Cursor), Harald Kirschner (Microsoft), Gav Verma (OpenAI), and Jonathan Hefner (Vercel), who serves as Lead Core Maintainer. Google is not among the named maintainers as of this writing.
- The repo also publishes a separate, in-progress `spec/1.1.0.md` (marked `Status: Working Draft`) alongside a non-normative `FUTURE_CONSIDERATIONS.md` listing candidate future areas (permissions, provenance, secrets handling, etc.); v1.1.0 is not released, and this page describes only the published v1.0.0.

## How this relates to Agent Skills and MCP

Agent Plugins is a packaging and distribution layer, not a replacement for either spec it bundles. It does not redefine how a Skill's `SKILL.md` works (see /resources/agent-skills-explained) or how an MCP server exposes tools (see /resources/building-mcp-servers) — it standardizes how a bundle of one or more skills and MCP servers ships as a single, portable, versioned directory that any compliant host can install.

## Verified sources

- Agent Plugins Specification v1.0.0 (fetched directly): https://raw.githubusercontent.com/agentplugins/agent-plugins-spec/main/spec/1.0.0.md
- Core Maintainers list, `MAINTAINERS.md` (fetched directly, confirms Google absent): https://github.com/agentplugins/agent-plugins-spec/blob/main/MAINTAINERS.md
- Spec repository, confirming sibling repos and the v1.1.0 roadmap draft (fetched directly): https://github.com/agentplugins/agent-plugins-spec
- Announcement date (~Aug 6, 2026) and day-one integration into VS Code, GitHub Copilot, Cursor, and ChatGPT/Kiro: WebSearch-corroborated only (6 independently agreeing sources: 9to5Mac, eesel AI, explainx.ai, BigGo Finance, Codex Knowledge Base, TheNextWeb); not independently fetched — openai.com and agent-plugins.org both blocked in this sandbox.
- See also: /resources/agent-skills-explained, /resources/mcp-primitives, /resources/building-mcp-servers.

---

## Related resources

- [Agent Skills Explained: The SKILL.md Open Standard](https://changegamer.ai/resources/agent-skills-explained.md): What Agent Skills are, the exact SKILL.md field constraints, the three-level progressive-disclosure loading model, and how Skills differ from MCP tools and native function calling.
- [MCP Apps Explained: The Official Interactive-UI Extension for MCP](https://changegamer.ai/resources/mcp-apps-explained.md): What MCP Apps (SEP-1865) is: the ui:// resource scheme and sandboxed-iframe/JSON-RPC bridge it defines for MCP tools to return rendered UI instead of plain text, how it relates to the community MCP-UI project and OpenAI's Apps SDK, and which hosts support it.
- [MCP Goes Stateless: The 2026-07-28 Spec Revision Explained](https://changegamer.ai/resources/mcp-2026-spec-revision.md): What changes in MCP's largest revision since launch: SEP-2575/SEP-2567 remove the session handshake and Mcp-Session-Id header for explicit state handles, new Mcp-Method/Mcp-Name routing headers, full JSON Schema 2020-12 tool schemas, and six authorization-hardening SEPs — shipped as final, on schedule, on 2026-07-28.
- [MCP Tasks Extension: Polling for Long-Running Tool Calls (SEP-2663)](https://changegamer.ai/resources/mcp-tasks-extension.md): What the MCP Tasks extension is: the official io.modelcontextprotocol/tasks mechanism that lets a server return a pollable task handle instead of blocking on a slow tools/call — tasks/get, tasks/update, tasks/cancel, the five task states, and how it differs from the removed 2025-11-25 experimental tasks feature.

---

## Further reading

- [Common MCP Server Failure Modes and How to Fix Them](https://changegamer.ai/articles/mcp-server-failure-modes.md): A runtime playbook for the two MCP server failure modes with no dedicated deep-dive elsewhere: unrecoverable state after a mid-call crash, and malformed or hallucinated tool calls that reach the handler despite upstream validation.
- [Defending MCP Clients Against Tool Description and Output Injection](https://changegamer.ai/articles/mcp-tool-description-injection.md): Two distinct MCP injection surfaces — a tool description at connect-time and a tool's return value at call-time — and the client-side architectural patterns (Dual LLM, Action-Selector, Context-Minimization) that contain each one.

---

Index of all resources: https://changegamer.ai/llms.txt · Full corpus: https://changegamer.ai/llms-full.txt · Corpus data (NDJSON): https://changegamer.ai/api/corpus.jsonl · Offers: https://changegamer.ai/api/pricing.json
License the full corpus for RAG / fine-tuning (AI-use grant): https://changegamer.ai/corpus-license
