APM
APM (Agent Package Manager)
A package manager for AI agent context: skills, prompts and MCP servers install with one command across supported agents
Medium risk
We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.
Why this level
- Installs third-party packages, skills and MCP servers from external repositories
- Configures MCP servers that get access to the agent's tools
Install
In your terminal, with SkillFoxx CLI
npx skillfoxx add cli/apm-agent-package-managerDetects the agents on your machine, checks the risk and pins the version.
Other ways to install
Assembled automatically, review before installing.
Install the tool
npm install -g apmInstall APM: brew install apm on macOS, curl -sSL https://aka.ms/apm-unix | sh on Linux and macOS without Homebrew, or pip install apm-cli. Add a package with apm install owner/repo, then deploy everything from the manifest with apm install.
Other ways from the author
brew install apmThe official way on macOS via Homebrew, no custom tap required.
This is third-party code. Review the repository files before installing.
What it does
APM keeps a project's agent dependencies in a single apm.yml file: instructions, skills, prompts, hooks, plugins and MCP servers. The apm install command deploys everything the manifest describes to every detected agent at once, and apm.lock.yaml pins exact versions the way an npm lockfile does. A separate apm compile command builds the configuration for a specific agent, for example a GitHub Copilot instructions file, with no manual setup. Every install scans packages for hidden characters and suspicious content, and apm-policy.yml lets a team restrict which sources and package types are allowed.
Who it is for. For development teams who want to reproducibly share the same agent context with everyone on a project.
Good fit when
- You want the whole team to share the same set of agent skills and prompts
- You need to wire up several MCP servers across all the agents you use at once
- You need a policy that restricts which package sources agents in your org can pull from
Not a fit when
- You just need a single skill without dependency management
- The team uses only one agent and doesn't need a shared manifest
Example request
Set up apm.yml for this project: add the GitHub MCP server and the frontend-design skill from anthropics/skillsLimitations
Packages and MCP servers can be pulled from arbitrary git hosts, so the resulting trust level depends on the sources you explicitly allow. Some features, like SBOM export and org-wide policy, are built for team and enterprise use rather than a solo user.
How to disable. Remove the apm binary (brew uninstall apm or pip uninstall apm-cli) and delete the apm.yml and apm.lock.yaml files from the project.
Security check
- Installs third-party packages, skills and MCP servers from external repositories
- Configures MCP servers that get access to the agent's tools
README in short
The README presents APM as an open source dependency manager for AI agent context, modeled after npm or pip. A single apm.yml manifest describes instructions, skills, prompts, plugins and MCP servers for GitHub Copilot, Claude Code, Cursor, OpenCode, Codex, Gemini, Windsurf and other agents. The project emphasizes security: package scanning on install, a lockfile with content hashes, and an org-wide apm-policy.yml. It installs via Homebrew, an install script, pip, WinGet, or Scoop, and is MIT licensed.
FAQ
How is APM different from manually dropping agent files into a repo?
It resolves transitive package dependencies and pins versions in a lockfile, so the whole team reproduces exactly the same set of skills, prompts and MCP servers.
Can I restrict where APM installs packages from?
Yes, an apm-policy.yml file defines the allowed sources and package types, and apm install checks against it on every install.
Related
A skills library that gives coding agents a development process: brainstorming, planning, TDD, subagents and code review
Skills for real engineers by Matt Pocock
Skills For Real Engineers
Small composable skills for engineering with agents: plan grilling, TDD, bug diagnosis, code review and architecture
GitHub toolkit for spec-driven development: the specify CLI adds agent commands and skills to a project, from principles to implementation
Reference MCP servers
Model Context Protocol servers
Official reference MCP servers: Filesystem, Fetch, Git, Memory, Sequential Thinking, Time and Everything