<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom"><title>Todd Schiller - Atlassian</title><link href="https://toddschiller.com/" rel="alternate"></link><link href="https://toddschiller.com/feeds/tag/atlassian.atom.xml" rel="self"></link><id>https://toddschiller.com/</id><updated>2026-08-07T00:00:00-04:00</updated><subtitle>Human ✘ Artificial Intelligence</subtitle><entry><title>This Week in Extensibility: six vendors standardize agent-plugin bundles, Mozilla stays neutral on WebMCP, Atlassian opens Rovo to Forge apps</title><link href="https://toddschiller.com/blog/extensibility-radar-2026-08-07.html" rel="alternate"></link><published>2026-08-07T00:00:00-04:00</published><updated>2026-08-07T00:00:00-04:00</updated><author><name>Todd Schiller</name></author><id>tag:toddschiller.com,2026-08-07:/blog/extensibility-radar-2026-08-07.html</id><summary type="html">Week of July 31 – August 7, 2026: six agent vendors publish a shared plugin-packaging standard, Mozilla files a neutral position on WebMCP that leaves the browser engines split, and Atlassian opens its Rovo agent framework to Forge apps.</summary><content type="html">&lt;!-- markdownlint-disable MD013 --&gt;
&lt;p&gt;The theme this week was a split between packaging and trust. Six rival agent
vendors agreed on how to bundle plugins while deliberately leaving security out
of scope, Chrome began enforcing store rules that police what an extension may
do, and the browser engines filed divergent positions on the API that would let
a page hand tools to a user's agent. The packaging layer is converging faster
than the trust layer underneath it.&lt;/p&gt;
&lt;h2&gt;Packaging: six vendors standardize agent-plugin bundles&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Amazon, Cursor's maker Anysphere, GitHub, Microsoft, OpenAI, and Vercel
published Agent Plugins 1.0.0, a vendor-neutral format for packaging agent
extensions.&lt;/strong&gt; The
&lt;a href="https://github.com/agentplugins/agent-plugins-spec"&gt;specification&lt;/a&gt;, announced
August 6 in a
&lt;a href="https://vercel.com/blog/introducing-agent-plugins"&gt;joint post from Vercel&lt;/a&gt;,
defines a bundle of a &lt;code&gt;plugin.json&lt;/code&gt; manifest, a &lt;code&gt;skills/&lt;/code&gt; folder, and an
&lt;code&gt;mcp.json&lt;/code&gt; file so one plugin installs across ChatGPT, Codex, Cursor, GitHub
Copilot, Kiro, and VS Code rather than being repackaged per client. It is
labeled a Working Draft, and it carries no permission model, sandboxing, code
signing, or secrets mechanism, with each of those
&lt;a href="https://aws.amazon.com/blogs/opensource/aws-supports-agent-plugins-an-open-standard-for-portable-agent-extensions/"&gt;deferred to future work&lt;/a&gt;;
every client keeps its own trust and marketplace decisions.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Why it matters:&lt;/strong&gt; the same customization, a set of Skills and MCP tools,
becomes portable across the major agent clients instead of tied to one vendor's
format, so a user is not re-installing per platform. The vendors standardized the
bundle while leaving the permission and signing model to each client, so the
portability is real and the safety guarantees are not yet part of the standard.&lt;/p&gt;
&lt;h2&gt;Standards: Mozilla files a neutral position on WebMCP&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Mozilla recorded a neutral position on WebMCP, leaving the three browser
engines split.&lt;/strong&gt; WebMCP lets a website expose in-page tools that a user's own
agent can call. Mozilla's
&lt;a href="https://github.com/mozilla/standards-positions/issues/1412"&gt;August 5 position&lt;/a&gt;
is neutral, while Apple's WebKit team has filed an
&lt;a href="https://github.com/WebKit/standards-positions/issues/670"&gt;oppose position&lt;/a&gt;
citing privacy, security, venue, and API-design concerns, and Google and
Microsoft are authoring the proposal. WebMCP remains a Web Machine Learning
Community Group draft shipping only as a Chrome origin trial, so there is no
cross-vendor agreement and no stable implementation.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Why it matters:&lt;/strong&gt; the API that would let any site offer tools to a user's agent
now has explicit, divergent positions from every engine, which points to a
contested track rather than one converging toward shared support. It does not
change that the only running implementation is a single browser's origin trial.&lt;/p&gt;
&lt;h2&gt;Marketplaces: Chrome Web Store begins enforcing its updated policies&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Chrome Web Store policy enforcement began August 1 across its extension
ecosystem.&lt;/strong&gt; Four
&lt;a href="https://developer.chrome.com/blog/cws-policy-updates-2026"&gt;policies published July 1&lt;/a&gt;
took effect: a Limited Use rule narrowing data collection to what is strictly
necessary for an extension's single disclosed purpose, a duty to notify users of
post-install changes to data handling, a Regulated Goods ban on extensions
enabling real-money prediction-market transactions, and a Malicious Products
clause that bans extensions built to circumvent an AI service's safety guardrails
or usage restrictions. Non-compliant extensions face enforcement after the date.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Why it matters:&lt;/strong&gt; a marketplace of this reach setting a hard rule against
extensions that defeat AI guardrails draws a governance line at the store level,
where the platform, not each AI service, decides that circumvention tooling is
not distributable.&lt;/p&gt;
&lt;h2&gt;Platforms: Atlassian opens Rovo to Forge apps and extends its Connect deadline&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Atlassian shipped an Early Access Rovo MCP Module that lets Forge apps expose
their actions as tools inside Rovo Studio.&lt;/strong&gt; The
&lt;a href="https://developer.atlassian.com/changelog/"&gt;August 3 changelog entry&lt;/a&gt; lets a
Forge app publish its actions as callable tools for makers building custom agents
in Rovo, extending the app platform into Atlassian's agent framework rather than
shipping a single agent. In the same window Atlassian
&lt;a href="https://community.developer.atlassian.com/t/connect-end-of-support-extended-to-january-31-2027/102002"&gt;extended Connect end-of-support to January 31, 2027&lt;/a&gt;,
moving the deadline out of the year-end crunch, and began direct outreach to
vendors still running Connect or hybrid apps so they migrate to Forge.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Why it matters:&lt;/strong&gt; it gives Marketplace developers a supported path to surface
their apps as tools inside Atlassian's agents, while the Connect deadline sets the
date by which the whole ecosystem must be on Forge to reach that surface at all.&lt;/p&gt;
&lt;h2&gt;Also worth knowing&lt;/h2&gt;
&lt;p&gt;&lt;strong&gt;Merge added a governed catalog of MCP connectors to its Agent Handler.&lt;/strong&gt; A
&lt;a href="https://www.merge.dev/changelog/week-5-july-2026"&gt;July 31 changelog&lt;/a&gt; lets a
company embedding Merge browse and enable hundreds of generic MCP connectors
alongside Merge-built ones on the same authentication, access-control, and
governance layer, and adds an AI Guardrails experience with PII detection and a
live rule tester.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Wasmtime patched two sandbox-integrity advisories across four release lines.&lt;/strong&gt;
The Bytecode Alliance shipped
&lt;a href="https://github.com/bytecodealliance/wasmtime/releases/tag/v47.0.3"&gt;v47.0.3&lt;/a&gt; and
matching v46, v36, and v24 releases on July 31 to fix two low-severity advisories
where engine type indices could be confused and where traps during bulk
operations could corrupt VM state. Backporting to the v24 long-term line reflects
Wasmtime's use as production plugin-isolation infrastructure.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;CopilotKit released a Channels SDK for running AG-UI agents in chat surfaces.&lt;/strong&gt;
The &lt;a href="https://www.copilotkit.ai/blog/introducing-channels-sdk"&gt;August 4 SDK&lt;/a&gt; runs
one AG-UI agent across Slack, Teams, and other chat platforms with generative UI,
human-in-the-loop approvals, and cross-channel memory. It is a developer library
for shipping agents rather than a customization surface handed to end users.&lt;/p&gt;
&lt;h2&gt;On the radar&lt;/h2&gt;
&lt;ul&gt;
&lt;li&gt;&lt;strong&gt;August 13–14:&lt;/strong&gt; MCP Dev Summit in Seoul, co-located with Open Source Summit
Korea.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;September 1:&lt;/strong&gt; Atlassian Forge Object Store &lt;code&gt;currentVersion&lt;/code&gt; field
deprecation takes effect.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;September 30:&lt;/strong&gt; Atlassian sunsets the &lt;code&gt;confluence:fullPage&lt;/code&gt; and
&lt;code&gt;jira:fullPage&lt;/code&gt; modules in favor of a unified &lt;code&gt;global:fullPage&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;&lt;strong&gt;January 31, 2027:&lt;/strong&gt; Atlassian Connect end-of-support; Marketplace and custom
apps must be on Forge.&lt;/li&gt;
&lt;/ul&gt;
&lt;hr /&gt;
&lt;p&gt;&lt;em&gt;This Week in Extensibility is curated by Todd Schiller. Research, drafting, and
fact checking are AI-assisted.&lt;/em&gt;&lt;/p&gt;
</content><category term="Extensibility"></category><category term="extensibility"></category><category term="plugins"></category><category term="sandboxes"></category><category term="web standards"></category><category term="MCP"></category><category term="WebMCP"></category><category term="Atlassian"></category><category term="Chrome"></category></entry></feed>