$npx skillfedfor your agent

apm-cli

MCP configuration tool

Worth itPyPI Build ToolsReleased Aug 2026101.8K downloads / mopermissive licensePure Python

Decision gist · record as of 2026-08-14

pure-Python wheel — apm_cli-0.28.0-py3-none-any.whl
v0.28.0 · released 2026-08-06 · Python >=3.10 · 18 runtime deps: click, colorama, pyyaml, requests, truststore, python-frontmatter, llm, llm-github-models

Yes. APM solves a real problem—reproducible, portable agent configuration—that has no established standard tool. It is actively maintained, has low install friction, carries a permissive MIT license, and integrates with major agent platforms. Install it if you manage agent setups across a team or need to version-control and audit agent dependencies. The 18 runtime dependencies are all common, well-maintained libraries (click, requests, GitPython, rich), so dependency risk is low.AI-flagged interpretation of the facts on this page — verify before relying

Before you install

  • Requires Python 3.10 or later; git must be available for repository operations.
  • Low friction: pure Python wheel with 18 runtime dependencies including click, requests, GitPython, and LLM integrations.
  • Active maintenance with a release 8 days ago.

License · maintenance · safety

permissive license (permissive) — MIT License permits commercial and private use with minimal restrictions. You may use, modify, and distribute the software freely provided you include the original copyright notice and license text.

last release 2026-08-06 (8 days)

0 known vulnerabilities (OSV.dev, 2026-08-14) · 101,837 downloads/mo, #12,911 on PyPI

Verify before relying

pip install apm-cli

apm install microsoft/apm-sample-package#v1.0.0

apm compile -t copilot
  • Whether APM's transitive dependency resolution handles circular dependencies or version conflicts in agent packages.
  • Performance characteristics when resolving large dependency trees across multiple git hosts.
  • Whether the security scanning (Unicode hijacking detection, content hashing) is cryptographically audited.
  • How policy enforcement behaves when a package violates apm-policy.yml rules in CI/CD contexts.
Same gist for agents: .md · .json

What it is and what it does

APM is a package manager designed specifically for AI coding agents. It lets you declare agent dependencies—skills, prompts, plugins, MCP servers, and agent configurations—in a single `apm.yml` manifest file, then installs and resolves them with transitive dependency support, just like npm or pip do for code. Every developer who clones your repository runs `apm install` and gets an identical, reproducible agent setup across Copilot, Claude, Cursor, and other supported agents.

The tool treats agent context as executable (since prompts are programs for LLMs) and enforces security by default: it scans for hidden Unicode that could hijack agent behavior, pins integrity hashes in a lockfile, and gates transitive MCP servers behind trust prompts. It also supports organizational governance through `apm-policy.yml`, letting security teams restrict which sources, scopes, and primitives developers can install. You can compile configurations into agent-specific formats (e.g., `.github/copilot-instructions.md` for Copilot) with a single command.

Use it for

  • Declare and share agent skills, prompts, and plugins across a team in one manifest file, ensuring every developer gets identical setup.
  • Install MCP servers into multiple agent clients (Copilot, Claude, Cursor) from a single `apm install` command.
  • Enforce organizational security policies on agent dependencies, blocking unapproved sources or primitives before they reach disk.
  • Export agent configurations as standard plugin.json packages or zipped distributions for sharing across teams.
  • Audit and detect drift in agent context by rebuilding from the manifest and comparing against the working tree.
  • Integrate agent dependency management into CI/CD pipelines using GitHub Actions or branch protection rules.

Worth the install?

AI-flagged interpretation of the facts on this page. Verify before relying on it.

Worth it

Yes.

APM solves a real problem—reproducible, portable agent configuration—that has no established standard tool. It is actively maintained, has low install friction, carries a permissive MIT license, and integrates with major agent platforms. Install it if you manage agent setups across a team or need to version-control and audit agent dependencies. The 18 runtime dependencies are all common, well-maintained libraries (click, requests, GitPython, rich), so dependency risk is low.

Install

apm-cli on PyPI

Before you install

Low friction: pure Python wheel with 18 runtime dependencies including click, requests, GitPython, and LLM integrations. Active maintenance with a release 8 days ago. Requires Python 3.10 or later.

Requires Python 3.10 or later; git must be available for repository operations.

License in practice

MIT License permits commercial and private use with minimal restrictions. You may use, modify, and distribute the software freely provided you include the original copyright notice and license text.

Quickstart

pip install apm-cli

apm install microsoft/apm-sample-package#v1.0.0

apm compile -t copilot

Verify before relying

  • Whether APM's transitive dependency resolution handles circular dependencies or version conflicts in agent packages.
  • Performance characteristics when resolving large dependency trees across multiple git hosts.
  • Whether the security scanning (Unicode hijacking detection, content hashing) is cryptographically audited.
  • How policy enforcement behaves when a package violates apm-policy.yml rules in CI/CD contexts.

Package facts

Licensepermissive license permissive
Python supportSupports the current Python release >=3.10
Install frictionLow. Pure-Python wheel
Runtime dependencies
18 packages
clickcoloramapyyamlrequeststruststorepython-frontmatterllmllm-github-modelstomlitomltomlkitrichrich-clickwatchdogGitPythonruamel.yamlfilelockwebsockets
MaintenanceActively maintained 8 days since the last release
First released
Downloads101,837 / month, #12,911 on PyPI 30-day window, as of 2026-08-14
Known vulnerabilitiesNone known OSV.dev, checked 2026-08-14
Classifiers
License :: OSI Approved :: MIT LicenseOperating System :: OS IndependentProgramming Language :: Python :: 3Programming Language :: Python :: 3.10Programming Language :: Python :: 3.11Programming Language :: Python :: 3.12Programming Language :: Python :: 3.9

Evidence: apm_cli-0.28.0-py3-none-any.whl

Tags

Capabilities
ai agent dependency manageragent configuration package managermcp server installeragent skills and plugins resolverportable agent context managerai agent manifest toolagent package lockfile
Topics
ai-agentsdependency-managementmcp-servers

Let your AI agent find packages like this

Example. Real query, live index.

You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.

wish › “ai agent dependency manager”

  • apm-cliAPM is a dependency manager and configuration tool for AI agents that…
  • boost-skill-cliboost-skill-cli is a package manager for AI coding skills that finds,…
  • google-antigravityBuilds and runs AI agents powered by Google's Gemini, handling the…

Give your agent the search over MCP, or paste the wish link into any chat.

More Build Tools packages

packaging Worth it
PyPI · Build Tools · released Aug 2026

Provides reusable utilities for Python packaging interoperability, including version handling, specifiers, markers, requirements, tags, and metadata parsing according to standards like PEP 440 and PEP 425.

Apache-2.0 OR BSD-2-Clausepure Python · 3.9+
2.2Bdownloads / mo
tqdm Worth it
PyPI · Libraries · released Jul 2026

Wraps any iterable to display a real-time progress bar in the terminal or Jupyter notebook, showing iteration count, elapsed time, and estimated time remaining.

copyleftpure Python · 3.8+
648.6Mdownloads / mo
pip Worth it
PyPI · Build Tools · released Aug 2026

pip is the standard installer for Python packages, enabling you to download and install packages from the Python Package Index and other indexes into your Python environment.

MITpure Python · 3.10+
617.5Mdownloads / mo
hatchling Worth it
PyPI · Python Modules · released Aug 2026

Hatchling is a standards-compliant Python build backend that handles packaging, metadata, and distribution of Python projects when configured in a project's pyproject.toml file.

MITpure Python · 3.10+
484.2Mdownloads / mo
grpcio-tools Worth it
PyPI · Build Tools · released Jul 2026

Generates Python gRPC service stubs and message classes from Protocol Buffer definitions, enabling developers to build gRPC clients and servers.

Apache-2.0compiled wheel · 3.10+
278.2Mdownloads / mo
pre-commit Worth it
PyPI · Build Tools · released Aug 2026

pre-commit is a framework for installing and running git hooks written in any language before commits are made, automating code quality and validation checks across multi-language projects.

Install it if your team needs consistent, automated validation at commit time.

permissive licensepure Python · 3.10+
179.9Mdownloads / mo

See also google-agents-cli · metagit-cli · scitex-dev · fast-agent-mcp · pdm-build-locked · elastic-apm · scout-apm · aip-agents-binary · deepagents-cli · ddapm-test-agent

Further reading