Karpathy's LLM Wiki and Garry Tan's GBrain are early clues to an open source agent renaissance. These are not normal apps. They are personal operating systems for agents: memory, skills, tools, workflows, and context that can be borrowed, modified, and shared.
AI makes software creation abundant. Open source makes it spread. Enterprises will need a trusted control layer for what gets reused.
Historically, these toolsets were reserved for elite engineers. Today, with agents like Codex and Claude, anyone can take pieces of these stacks, modify them, and build their own version. The next wave of developers will not just be engineers. It will include knowledge workers.
LLM Wiki is a good example. It gives an agent persistent memory and context compiled into a living knowledge base. GBrain points in a similar direction: a personal or company brain that agents can operate against. These systems are early, but the pattern is powerful. People are going to assemble personal operating systems for their agents from open source projects, borrowed skills, internal tools, and company-specific context.
That creates a new enterprise problem.
If I pull a skill from GitHub, use it at work, and share it with colleagues, how do we know it is safe? Which data can it touch? Who maintains it? Can it exchange context with the company's broader agent fabric? And if five teams customize the same public framework, who has the canonical version?
As open source agents, skills, model artifacts, and internal tools spread, the bottleneck shifts from creation to verification.
This is why JFrog is interesting.
JFrog is already a control layer for software artifacts. It helps companies understand which software objects are approved, secure, governed, and safe to ship. In a world where agents create and reuse more software objects, that role becomes more valuable.
Enterprises will need an internal app store for agentic software: a governed registry where teams can discover approved skills, trusted agents, safe MCP servers, verified model artifacts, and maintained internal tools. That registry needs provenance, ownership, permissions, and security. It also needs to prevent every team from rebuilding the same thing in slightly different ways.
JFrog's edge is breadth. Large enterprises rarely live in one cloud, one package manager, or one AI toolchain. JFrog supports 40+ package technology types, hybrid and multi-cloud environments, and newer AI surfaces such as model artifacts, IDE extensions, MCP servers, and skills.
The numbers support the direction of the thesis. In Q1 2026, JFrog grew revenue 26%, cloud revenue 50%, reported 120% net dollar retention, and had $574.9M of remaining performance obligations. Its 2026 supply-chain report also analyzed 18.2B artifacts across the JFrog Platform and flagged 495 malicious Hugging Face models, 56 malicious OpenVSX extensions, and 969 malicious AI agent skills.
AI makes software creation abundant. Open source makes it spread. Abundance creates a coordination problem. Enterprises will need trusted systems that govern what can be reused safely.
Sources