Dev.to
5/8/2026

AGENTS.md moved AI performance up a model tier. Package trust needs the same.
Short summary
Structured discovery conventions like AGENTS.md improved AI agent performance by the equivalent of one model tier, and 60,000 projects adopted it. Yet a critical gap remains: AI agents installing npm packages lack access to behavioral trust scores or security commitment records. The author argues for structured trust signals at the install-decision point, mirroring how robots.txt and schema markup guide machine consumers.
- •AGENTS.md convention improved agent task performance equivalently to a model tier upgrade
- •60,000 open-source projects adopted the discovery pattern since August 2025
- •Missing layer: npm packages lack trust signals at the point where AI agents make install decisions
Generated with AI, which can make mistakes.
Is this a good recommendation for you?



