Rebuilding the same extension for every product

What Agent Plugins defines is plain: a directory holding a manifest file called plugin.json. Version 1.0.0 carries two components, with reusable instructions and workflows on the Agent Skills side and the connections that link an agent to tools and data on the MCP server side. The work that disappears for a developer is repackaging the same extension into each product's own folder structure and setup steps. The joint signature of Amazon, Cursor, Microsoft, OpenAI and Vercel reduces that packaging tax to one format.[1]

What the format leaves out shapes it as much as what it covers. The specification excludes marketplaces, permissions and runtime environments; the portable part is the package and how it is found, while what an extension may actually do at runtime, and with what authority, stays product-specific. To my reading that puts the portability at the formal layer. Another reading is available: permissions and runtime may have been deliberately deferred because security boundaries genuinely differ from product to product.[1]

The signature that is not there

Both components the format wraps were released as open standards by Anthropic: the Model Context Protocol and Agent Skills. The company recently added its own plugin system to Cowork, its desktop tool, and it is not part of this effort. The specification is being developed in the open on GitHub, so the door does not look technically closed.[1]

What will show that a format has genuinely become shared is an installation rather than an announcement. If the same extension runs unchanged in two of the five products from a single plugin.json, with permission prompts as the only visible difference, the portability claim has been tested. If no such case is published by 31 October 2026, the specification stays a shared statement of intent rather than a shared habit.[1]