Tutorial
What are Google Agent Plugins in 2026? How Skills, MCP servers, plugins, and JSON Schema form the next agent tool stack
The skill is written, the MCP server works, and the next coding agent still needs a different wrapper. What 2026 is short on is not tools. It is a box that can travel.
On 6 August 2026 Google said on the Developers Blog that it was joining the Agent Plugins technical steering committee and wiring the format into its own products. On 10 September the Google Cloud Developer Plugin shipped: auth, projects, gcloud guardrails, and the Developer Knowledge MCP server in one installable bundle for Antigravity, Claude Code, Codex, and Cursor. It is easy to hear that as “Google invented another tool protocol.” It did not. Agent Skills already say how a skill is written. MCP already says how a tool is called. What was missing is a box that holds both in one directory and does not fork when you change clients. The contract for that box is two closed JSON files: plugin.json and mcp.json. What is MCP covers the protocol; MCP and JSON Schema covers inputSchema. This article is only how the four layers stack: Plugin, Skills, MCP server, JSON Schema. Spec: Agent Plugins 1.0.0.
Not another MCP primer: the plugin is the box
Pin the layers. A skill is the brief the model reads: when to use it, how to walk the workflow, which scripts and references sit beside it. An MCP server is the hand the runtime uses: tools/list exposes tools, tools/call runs them, arguments are JSON. A plugin reinvents neither. It says: the root must have plugin.json; skills are discovered only from immediate children of skills/; MCP is read only from root mcp.json. v1 admits exactly those two component types. Commands, sub-agents, and hooks go in a reverse-domain directory such as com.example.client/—other clients may ignore it.
Google says the same thing in public: not every skill should become a plugin. One MCP server for one client is still simpler as native config. A single SKILL.md does not need a box. A plugin earns its keep when several pieces must travel together: the MCP that queries invoices, the skill that turns the result into a weekly summary, and a discovery contract that must not live in a third file. Switching Cursor, Claude Code, or Antigravity should not mean a second directory layout and a second manifest dialect.
The spec deliberately skips install, distribution, permissions, sandboxing, and trust. Those are obligations of an IDE, a CLI, or a managed platform; baking them into portable fields would fork on day one. Agent Plugins is a package format. Discovery can sit in another layer (Google mentions Agentic Resource Discovery and an AI Catalog). Execution still sits on MCP and Agent Skills. Adopting one layer never buys you the next. Keep this sentence: the box is portable; the install UX does not have to be.
| Layer | What it is | Where the contract lives |
|---|---|---|
| Plugin | A distributable directory that ships components that belong together | plugin.json (closed fields) |
| Skill | Reusable workflow text, scripts, and references | skills/<name>/SKILL.md |
| MCP server | Runtime and transport for tools and resources | Root mcp.json plus the MCP protocol |
| JSON Schema | The shape of the manifest, the MCP config, and tool arguments | Official plugin.schema.json / mcp.schema.json, plus inputSchema |
plugin.json: a closed manifest and its JSON Schema
A client must read root plugin.json before it discovers components. The file must be a JSON object, and the schema is closed: only $schema, name, version, description, author, homepage, repository, license, keywords, and extensions. Extra top-level fields must be reported and ignored; they do not reject the plugin. What is fatal is a missing required field, a wrong type, or an illegal name—then the whole package stays unloaded. For 1.0.0, $schema must be https://agent-plugins.org/schemas/1.0.0/plugin.schema.json. Clients use it to pick local validation rules and must not fetch a schema while loading a plugin.
name is not a free-form display string. Length 1–64, lowercase letters, digits, hyphens, and dots only; first and last characters alphanumeric; no -- or ... My-Plugin and -start are invalid. SemVer is recommended for version, but a client must not reject a manifest only because the string “does not look like SemVer.” The author object may contain only name, email, and url. Client-private data goes under extensions.com.example.client. Do not invent a fifth top-level key for hooks.
Notice what the manifest cannot do: it cannot relocate components, and it cannot inline skills or MCP servers. There is no discovery path to configure and no precedence to learn. If skills/ exists, load skills; if it does not, skip—that is not an error. Below is a slightly fuller, still legal manifest. Confirm it parses, then check fields against the official schema.
{
"$schema": "https://agent-plugins.org/schemas/1.0.0/plugin.schema.json",
"name": "reports-plugin",
"version": "1.0.0",
"description": "Query invoices and write the weekly finance summary",
"license": "Apache-2.0",
"keywords": ["finance", "reports", "mcp"],
"homepage": "https://example.com/plugins/reports",
"repository": "https://github.com/example/reports-plugin"
}
Skills: SKILL.md in a fixed directory
Agent Plugins does not rewrite the skill format. Agent Skills owns frontmatter, body, and the scripts/, references/, assets/ layout. Plugins only define discovery. The fixed location is skills/. Each immediate child directory that contains a regular file named exactly SKILL.md is one skill. Clients must not recurse for more skills—a second skill hidden at skills/deploy/extra/SKILL.md is invisible.
If one skill is invalid, the client must skip it, keep loading other skills and other component types, and should report which one failed. That is the opposite of “one MCP crash kills the package.” Google’s line is: independent components fail independently. A broken weekly-summary skill must not take down the invoice MCP, and the reverse. For a coding agent that matters: a typo in a docs skill’s frontmatter should not remove your gcloud guardrails.
A skill owns context, not transport. It tells the model “check the project first, then billing, and do not commit keys.” Changing cloud resources still happens through MCP tools or local scripts. Pasting a whole manual into the system prompt eats the window. Skills load on demand—the point the Cloud Developer Plugin post keeps making. Installing skills one by one gets messy; related skills and MCP servers should ship as a bundle. The plugin is that cord, not a second tool-calling API.
mcp.json: how servers are found, and which layer JSON Schema owns
The MCP wire protocol stays MCP: initialize, tools/list, tools/call, stateless HTTP. Agent Plugins only answers where to connect. Config must live at root mcp.json. It must not be inlined in plugin.json and must not use another core path. The top level may contain only $schema and mcpServers. For 1.0.0, $schema must be https://agent-plugins.org/schemas/1.0.0/mcp.schema.json and must match the Agent Plugins version declared by the manifest. A mismatch disables MCP for that plugin and leaves skills loading.
Every server needs an explicit type. A client must not infer transport from the shape of the object. stdio needs a command (one executable token, not a shell string) plus optional args / env / cwd; a bundled binary must use a ./-prefixed plugin-relative path. streamable-http and optional legacy sse need an absolute URL. Non-loopback hosts must be HTTPS. The spec is blunt: do not put secrets in headers; OAuth and credentials are client-managed, not portable fields. An invalid entry, an unsupported transport, or a failed handshake skips only that server.
JSON Schema shows up three times. Do not mash them into one file. First, the package contracts: plugin.schema.json and mcp.schema.json—can the plugin be discovered. Second, tool inputs: MCP inputSchema—do the model’s arguments look right. Third, your business API’s OpenAPI or structured output. If the first fails, the client never enters the box. If the second fails, tools/call dies at runtime. The validation chain is in the MCP Schema article above. Below is an mcp.json with local stdio and remote Streamable HTTP.
{
"$schema": "https://agent-plugins.org/schemas/1.0.0/mcp.schema.json",
"mcpServers": {
"invoice-tools": {
"type": "stdio",
"command": "./bin/invoice-mcp",
"args": ["--data", "${PLUGIN_DATA}/invoices"],
"cwd": "${PLUGIN_ROOT}"
},
"docs": {
"type": "streamable-http",
"url": "https://docs.example.com/mcp"
}
}
}
{
"name": "searchInvoices",
"description": "Query invoices by date range and status",
"inputSchema": {
"type": "object",
"properties": {
"startDate": { "type": "string", "format": "date" },
"endDate": { "type": "string", "format": "date" },
"status": { "type": "string", "enum": ["draft", "sent", "paid"] }
},
"required": ["startDate", "endDate"]
}
}
What Google shipped in 2026: Developer Plugin, Agents CLI, Data Agent Kit
Stack the two announcements. August: join the TSC (Amazon, Cursor, Microsoft, OpenAI, and Vercel were already core maintainers) and start supporting the format in Google products. September: publish the flagship google-cloud-developer bundle on google/skills. It is not “another gcloud wrapper.” It is a foundational plugin: auth, projects, gcloud guardrails, plus Developer Knowledge MCP so the agent grounds on current official docs instead of a year-old blog. Install goes through each client’s marketplace or CLI. Keys stay in environment variables, not in mcp.json headers—which is exactly the spec refusing to make secrets portable.
Two other lines sit in the same ecosystem. Agents CLI packages ADK scaffolding, eval, deploy, observability, and publish so Antigravity, Gemini CLI, Claude Code, and Cursor become competent at building agents on Google Cloud. Data Agent Kit packages skills and MCP servers for BigQuery, Spanner, Cloud SQL, and the rest of the data plane. Both could already ship skills. They now use a directory layout that is not Google-private. Your invoice plugin and Google’s cloud plugin validate against the same schemas.
Do not mix this with A2A. A plugin answers “how does this agent gain a set of skills and tools.” An A2A Agent Card answers “how is another agent discovered and delegated to.” MCP inside the box is still a downward hand. Lateral colleagues are still Agent Cards and Tasks. Layers: A2A vs MCP. Wrap a whole remote agent as one tool in mcp.json and multi-turn clarification plus async callbacks will burst the function-call shape.
| What Google is shipping | What is in the box | What you use it for |
|---|---|---|
google-cloud-developer | Cloud foundation skills + Developer Knowledge MCP | Any compatible client that must do GCP auth and docs |
| Agents CLI plugin | ADK lifecycle skills (scaffold / eval / deploy) | A coding agent that must do agent engineering on Cloud |
| Data Agent Kit | BigQuery, Spanner, Cloud SQL skills and MCP | Data pipelines and queries that should follow the agent, not one IDE |
Check both contracts in JSONVue
Before you publish, keep four fixtures: a legal plugin.json, a manifest with one extra top-level field, a legal mcp.json, and an entry whose command is ../bin/escape. The first must pass the official schema. The second should be reported and ignored—the plugin still loads. If your CI treats that as fatal, you are stricter than the client; know it. The third checks type and paths. The fourth must fail: a relative path that escapes the plugin root is a hard error.
Keep a fifth fixture: a tool inputSchema and one real tools/call arguments object. A green package contract does not mean the model filled dates correctly. Do not stuff both schemas into one “generic validate” file. One file is discovery; the other is invocation. Developer Knowledge MCP uses an API key at the client runtime. What you validate in git is an mcp.json with no secrets.
You can do this in the browser:JSON formatto see whether both manifests parse;JSON Schema validatorto check $schema, name, and mcpServers;JSON Diffto compare the repo mcp.json with a client-native export. Data stays on this machine. Further reading:MCP and JSON Schema, what MCP is, and how A2A and MCP split the work.
Related: What is MCP, MCP and JSON Schema, A2A vs MCP, What is an AI Agent.
FAQ
Is Agent Plugins a Google-proprietary format?
No. 1.0.0 is published by an open TSC. Core maintainers include Amazon, Cursor, Microsoft, OpenAI, and Vercel; Google joined in August 2026. The Google Cloud Developer Plugin is one package that conforms, not the spec. Your plugin does not have to live in google/skills to be an Agent Plugin.
I have one skill. Should I wrap it in a plugin?
Usually no. Google said it in the announcement: a single skill, a single MCP server, or a single client is simpler with native install. Box it when two or more things must ship together—say an MCP that queries numbers and a skill that writes the weekly summary. Boxing early only adds a manifest to maintain.
Is plugin.json the same as Gemini CLI’s gemini-extension.json?
No. Gemini CLI still has its own extension manifest, and MCP can live inside gemini-extension.json. Agent Plugins pushes MCP to root mcp.json; the manifest is closed and cannot inline components. Clients map the portable format onto native config. Diff the two files in JSONVue instead of guessing field aliases.
Does validating plugin.json replace validating inputSchema?
No. The manifest schema only answers “can this package be discovered.” The tool schema answers “are this hop’s arguments legal.” The first can pass while startDate is still missing. Two contracts, two checks. Do not share a “just parse it” helper.
Summary and next steps
Google Agent Plugins in 2026 collapse to one sentence: an open package format that puts already-portable Skills and MCP servers in fixed directories. Google uses it to ship the Cloud Developer Plugin, Agents CLI, and Data Agent Kit—not to invent a fourth tool protocol.
Ship in this order: make plugin.json parse, keep name legal, pin $schema to 1.0.0; then decide whether you need skills/ and mcp.json; then check the package contracts with the official schemas and tool arguments with a second schema. Keep fixtures in JSONVue. Protocol detail lives in the MCP articles; cross-agent delegation lives in the A2A article.