APM

APM (Agent Package Manager)

A package manager for AI agent context: skills, prompts and MCP servers install with one command across supported agents

CLIEditors’ pick

Medium risk

We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.

Why this level

  • Installs third-party packages, skills and MCP servers from external repositories
  • Configures MCP servers that get access to the agent's tools
All reasons and checks

microsoft/apm

Install

In your terminal, with SkillFoxx CLI

npx skillfoxx add cli/apm-agent-package-manager

Detects the agents on your machine, checks the risk and pins the version.

Other ways to install

Assembled automatically, review before installing.

Install the tool

npm install -g apm

You will need: Node.js

Checked against the repository on Sep 26, 2026, commit cd22403.

Text for your agent

Install APM: brew install apm on macOS, curl -sSL https://aka.ms/apm-unix | sh on Linux and macOS without Homebrew, or pip install apm-cli. Add a package with apm install owner/repo, then deploy everything from the manifest with apm install.

Other ways from the author
brew install apm

The official way on macOS via Homebrew, no custom tap required.

This is third-party code. Review the repository files before installing.

What it does

APM keeps a project's agent dependencies in a single apm.yml file: instructions, skills, prompts, hooks, plugins and MCP servers. The apm install command deploys everything the manifest describes to every detected agent at once, and apm.lock.yaml pins exact versions the way an npm lockfile does. A separate apm compile command builds the configuration for a specific agent, for example a GitHub Copilot instructions file, with no manual setup. Every install scans packages for hidden characters and suspicious content, and apm-policy.yml lets a team restrict which sources and package types are allowed.

Who it is for. For development teams who want to reproducibly share the same agent context with everyone on a project.

Good fit when

  • You want the whole team to share the same set of agent skills and prompts
  • You need to wire up several MCP servers across all the agents you use at once
  • You need a policy that restricts which package sources agents in your org can pull from

Not a fit when

  • You just need a single skill without dependency management
  • The team uses only one agent and doesn't need a shared manifest

Example request

Set up apm.yml for this project: add the GitHub MCP server and the frontend-design skill from anthropics/skills

Limitations

Packages and MCP servers can be pulled from arbitrary git hosts, so the resulting trust level depends on the sources you explicitly allow. Some features, like SBOM export and org-wide policy, are built for team and enterprise use rather than a solo user.

How to disable. Remove the apm binary (brew uninstall apm or pip uninstall apm-cli) and delete the apm.yml and apm.lock.yaml files from the project.

Security check

  • Installs third-party packages, skills and MCP servers from external repositories
  • Configures MCP servers that get access to the agent's tools

README in short

The README presents APM as an open source dependency manager for AI agent context, modeled after npm or pip. A single apm.yml manifest describes instructions, skills, prompts, plugins and MCP servers for GitHub Copilot, Claude Code, Cursor, OpenCode, Codex, Gemini, Windsurf and other agents. The project emphasizes security: package scanning on install, a lockfile with content hashes, and an org-wide apm-policy.yml. It installs via Homebrew, an install script, pip, WinGet, or Scoop, and is MIT licensed.

FAQ

How is APM different from manually dropping agent files into a repo?

It resolves transitive package dependencies and pins versions in a lockfile, so the whole team reproduces exactly the same set of skills, prompts and MCP servers.

Can I restrict where APM installs packages from?

Yes, an apm-policy.yml file defines the allowed sources and package types, and apm install checks against it on every install.

Editors’ pick

A skills library that gives coding agents a development process: brainstorming, planning, TDD, subagents and code review

PluginMedium riskNo VPN needed292.5KRepository stars
Editors’ pick

Small composable skills for engineering with agents: plan grilling, TDD, bug diagnosis, code review and architecture

SkillLow risk271.4KRepository stars
Editors’ pick

GitHub toolkit for spec-driven development: the specify CLI adds agent commands and skills to a project, from principles to implementation

CLIMedium riskNo VPN needed139.3KRepository stars

Reference MCP servers

Model Context Protocol servers

Official

Official reference MCP servers: Filesystem, Fetch, Git, Memory, Sequential Thinking, Time and Everything

MCP serverMedium risk90.6KRepository stars
Foxx AIAPM

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.