Agent Marketplace
# Agent Marketplace **Plugin lifecycle management for the Agent Governance Toolkit โ discover, install, verify, and sign plugins** *Part of the [Agent Governance Toolkit](https://github.com/microsoft/agent-governance-toolkit)* [](https://github.com/microsoft/agent-governance-toolkit/actions/workflows/ci.yml) [](../../LICENSE) [](https://python.org) [](https://pypi.org/project/agentmesh-marketplace/)
Note: This package was extracted from
agentmesh.marketplace. The old import path still works via a backward-compatibility shim but new code should import fromagent_marketplacedirectly.
What is Agent Marketplace?¶
Agent Marketplace provides governed plugin lifecycle management for AI agent ecosystems:
- Plugin Discovery โ Browse and search registered plugins by capability, trust level, or framework
- Verified Installation โ Install plugins with cryptographic integrity verification (SHA-256 + Ed25519)
- Plugin Signing โ Sign plugin manifests with Ed25519 keys for supply-chain security
- Manifest Validation โ Declarative plugin manifests with schema validation (capabilities, permissions, dependencies)
- Registry Management โ Register, update, and deprecate plugins with version tracking
Quick Start¶
from agent_marketplace import PluginRegistry, PluginInstaller, PluginManifest
# Create a registry
registry = PluginRegistry()
# Register a plugin
manifest = PluginManifest(
name="web-search",
version="1.0.0",
capabilities=["search", "browse"],
permissions=["network:read"],
)
registry.register(manifest)
# Install with verification
installer = PluginInstaller(registry=registry, verify_signatures=True)
result = installer.install("web-search")
CLI¶
# List available plugins
agentmesh-marketplace list
# Install a plugin
agentmesh-marketplace install web-search
# Verify plugin integrity
agentmesh-marketplace verify web-search
# Sign a plugin manifest
agentmesh-marketplace sign manifest.yaml --key signing-key.pem
Ecosystem¶
Agent Marketplace is one of 7 packages in the Agent Governance Toolkit:
| Package | Role |
|---|---|
| Agent OS | Policy engine โ deterministic action evaluation |
| AgentMesh | Trust infrastructure โ identity, credentials, protocol bridges |
| Agent Runtime | Execution supervisor โ rings, sessions, sagas |
| Agent SRE | Reliability โ SLOs, circuit breakers, chaos testing |
| Agent Compliance | Regulatory compliance โ GDPR, HIPAA, SOX frameworks |
| Agent Marketplace | Plugin lifecycle โ discover, install, verify, sign (this package) |
| Agent Lightning | RL training governance โ governed runners, policy rewards |
License¶
MIT โ see LICENSE.