Urgent.News

What's breaking now, across thousands of outlets.

Tech

Agent Plugins Package Capabilities. IRC-A Asks: Who Authorizes Them at Runtime?

Yesterday I stumbled on a LinkedIn post about a new open standard for packaging Agent Skills and MCP servers: Agent Plugins , built with collaboration from players like Vercel, OpenAI, Microsoft, AWS, GitHub and Cursor. I won't lie: at first, I felt that familiar punch in the stomach. A while ago, I had already felt the first signal when I read an article by @lukeocodes about the transformation…

Yesterday, I came across a LinkedIn post discussing a new open standard called Agent Plugins, created through collaboration from companies like Vercel, OpenAI, Microsoft, AWS, GitHub, and Cursor. This development initially felt familiar, reminiscent of my own exploration of stateless Internet Relay Chat for Agents (IRC-A) over the past month.

Agent Plugins addresses a real problem: packaging agent skills and MCP servers in a shared format, enhancing portability and reducing repetitiveness within the ecosystem. However, this packaging brings about another question: how do we govern the execution of these packaged capabilities?

I've been pondering this issue, particularly in the context of multi-agent systems that often resemble tightly coupled graphs. These systems currently struggle with hard-coded flows, excessive tool schema prompts, and overly privileged conversational agents. Production systems cannot rely on hope; they require robust governance.

IRC-A aims to tackle these concerns by introducing software engineering principles such as Smalltalk-style message passing, IRC-like logical channels, capability pooling, secure-by-default SDK base classes, and a strict separation between reasoning and execution.

The proposed architecture involves stateless cognitive agents that reason, delegate, and compose answers without owning database drivers or long-lived credentials. A BFA Gateway serves as the registry, governance layer, and semantic customs office, responsible for registering identities, capabilities, channels, and issuing short-lived authorization. Capabilities are discovered semantically through the gateway, which resolves relevant capabilities via a vector index rather than embedding tool schemas in prompts.

Execution occurs through isolated MCP tool servers, holding physical connections to databases and enterprise APIs. Authorization utilizes ephemeral delegated execution tokens, with the gateway creating short-lived signed tokens and receiving tools verifying them offline.

This approach aims to minimize prompt bloat, reduce coupling, enhance auditability, improve resilience, and limit the blast radius when errors occur. While I'm not competing with Vercel, I believe their ecosystem aligns with my vision.

As an Argentine developer, I admire Vercel's push in this space, as Guillermo Rauch shares my nationality. I hope my ideas find a receptive audience within that community.

Agent Plugins is crucial for portability, and IRC-A offers complementary secure runtime governance. Ultimately, both are essential for the next generation of agents, which will require both portable capabilities and controlled execution. I am committed to building the SDK, framework, diagrams, whitepaper, and promoting this conversation, door-to-door.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

Introducing Fylgja UI

Fylgja CSS has always focused on the layer below components. Good defaults, design tokens, and utilities that let you build whatever you need. But one question kept coming back.

More from Wednesday 12 August →