Discussion about this post

User's avatar
Youssef Elmaraghy's avatar

That's a reputation and permissions problem wearing an interoperability costume. "Trust" here isn't really about whether the plugin's code is good, it's about whether the agent (or the person who owns the agent) can afford to be wrong about it. Which makes me think the winning model borrows more from package managers with sandboxing and signed provenance than from app stores with manual review — review doesn't scale to the volume, but a blast radius does.

Youssef Elmaraghy's avatar

The independent-failure design is the detail I'd bet on more than the packaging spec itself. Most "standard" proposals die because they assume a clean adoption path, but real systems fail partially, not wholesale — an MCP server going down without taking your skills with it is the kind of boring reliability decision that actually survives contact with production. My guess on your closing question: we get real interoperability at the plugin layer (too useful to skip) but vendors still fight over the discovery/trust layer, since that's where the actual lock-in value sits.

2 more comments...

No posts

Ready for more?