🪨 why use many token when few token do trick — Claude Code skill that cuts 65% of tokens by talking like caveman
Agent package manager for agent configs and MCP
APM reads an `apm.yml` manifest and installs the agent pieces your project needs, including skills, prompts, agents, hooks, plugins, and MCP servers. It resolves dependencies, writes a lockfile, and can compile client-specific output such as `.github/copilot-instructions.md`. It also adds policy controls and security checks so teams can limit what gets installed and detect drift or tampering.
Builders who want one manifest to set up agent context across multiple AI coding tools.
You can clone a repo and reproduce the same agent setup without hand-copying prompts, skills, or integrations.
What it does
Manifest-based installs
Uses `apm.yml` to declare agent dependencies and `apm.lock.yaml` to pin the resolved tree.
Cross-client support
Targets Copilot, Claude Code, Cursor, Codex, Gemini, Windsurf, Grok, and other agent clients.
Transitive dependency resolution
Resolves packages that depend on other packages, like a normal dependency manager.
Plugin authoring and packing
Supports authoring plugins and exporting standard `plugin.json` packages, plus `apm pack` for distribution.
Policy and audit checks
Enforces `apm-policy.yml`, scans for hidden Unicode, and supports `apm audit` for drift and content checks.
MCP server installation
Installs MCP servers into detected clients and handles trust boundaries for transitive servers.
How to get it
- 1Run
git clone <org/repo> && cd <repo> apm install # every agent is configured
- 2Coming from npx skills add? Drop-in
apm install vercel-labs/agent-skills # whole bundle, like npx skills add apm install vercel-labs/agent-skills --skill deploy-to-vercel # one skill, persisted to apm.yml
- 3Zero-config Copilot
apm compile -t copilot # writes .github/copilot-instructions.md
- 4GitHub rulesets integration — wire apm audit --ci into branch protection
brew install apm
- 5No custom tap is required. Homebrew manages installation and updates: use brew upgrade…
curl -sSL https://aka.ms/apm-unix | sh
- 6Run
irm https://aka.ms/apm-windows | iex
README
APM – Agent Package Manager
An open-source, community-driven dependency manager for AI agents.
Think package.json, requirements.txt, or Cargo.toml — but for AI agent configuration.
GitHub Copilot | Claude Code | Grok Build | Cursor | OpenCode | Codex | Gemini | Windsurf | Kiro
Documentation · Quick Start · CLI Reference · v0.29 Roadmap
Portable by manifest. Secure by default. Governed by policy. One file describes every agent's context; one command reproduces it everywhere; one policy controls what an org will allow.
Why APM
AI coding agents need context to be useful — standards, prompts, skills, plugins — but today every developer sets this up manually. Nothing is portable nor reproducible. There's no manifest for it.
APM fixes this. Declare your project's agentic dependencies once in apm.yml, and every developer who clones your repo gets a fully configured agent setup in seconds — with transitive dependency resolution, just like npm or pip. It's also the first tool that lets you author plugins with a real dependency manager and export standard plugin.json packages.
# apm.yml — ships with your project
name: your-project
version: 1.0.0
dependencies:
apm:
# Skills from any repository
- anthropics/skills/skills/frontend-design
# Plugins
- github/awesome-copilot/plugins/context-engineering
# Specific agent primitives from any repository
- github/awesome-copilot/agents/api-architect.agent.md
# A full APM package with instructions, skills, prompts, hooks...
- microsoft/apm-sample-package#v1.0.0
mcp:
# MCP servers -- installed into every detected client
- name: io.github.github/github-mcp-server
transport: http # MCP transport name, not URL scheme -- connects over HTTPS
git clone <org/repo> && cd <repo>
apm install # every agent is configured
Coming from npx skills add? Drop-in:
apm install vercel-labs/agent-skills # whole bundle, like npx skills add
apm install vercel-labs/agent-skills --skill deploy-to-vercel # one skill, persisted to apm.yml
Same install gesture. You also get a manifest, lockfile, and reproducibility.
Zero-config Copilot:
apm compile -t copilot # writes .github/copilot-instructions.md
One command, no configuration -- VS Code and GitHub Copilot read the file automatically. APM dogfoods this target on its own repository.
The three promises
1. Portable by manifest
One apm.yml describes every primitive your agents need — instructions, skills, prompts, agents, hooks, plugins, MCP servers — and apm install reproduces the exact same setup across every client on every machine. apm.lock.yaml pins the resolved tree the way package-lock.json does for npm.
- One manifest for everything -- declared once, deployed across Copilot, Claude, Grok Build, Cursor, OpenCode, Codex, Gemini, Windsurf, Kiro
- Install from anywhere — GitHub, GitLab, Bitbucket, Azure DevOps, GitHub Enterprise, Gitea, Gogs, any git host
- Transitive dependencies — packages can depend on packages; APM resolves the full tree
- Author plugins — build Copilot, Claude, and Cursor plugins with dependency management, then export standard
plugin.json - Marketplaces — install plugins from curated registries in one command, deployed across all targets and locked
- Pack & distribute —
apm packbundles your configuration as a zipped package or a standalone plugin - CI/CD ready — GitHub Action for automated workflows
2. Secure by default
Agent context is executable in effect — a prompt is a program for an LLM. APM treats it that way. Every install scans for hidden Unicode that can hijack agent behavior; the lockfile pins integrity hashes; transitive MCP servers are gated by trust prompts.
- Content security —
apm installblocks compromised packages before agents read them;apm auditruns the same checks on demand - Lockfile integrity —
apm.lockrecords resolved sources and content hashes for full provenance - SBOM export —
apm lock export --format cyclonedx|spdxemits a standard inventory of what reached disk, straight from the lockfile — provenance for procurement, not a compliance attestation - Drift detection —
apm auditrebuilds your agent context in scratch and diffs it against your working tree to catch hand-edits before they ship - MCP trust boundaries — transitive MCP servers require explicit consent
3. Governed by policy
apm-policy.yml lets a security team say "these are the only sources, scopes, and primitives this org will allow" and have every apm install enforce it — with tighten-only inheritance from enterprise to org to repo, a published bypass contract, and audit-mode CI gates.
apm-policy.yml governs what gets installed; your agent harness governs what runs. The two planes do not overlap.
- Governance Guide — the canonical enterprise reference: enforcement points, bypass contract, air-gapped story, failure semantics, rollout playbook
- Policy reference — every check, every field, every default
- Adoption playbook — staged rollout from warn to block across hundreds of repos
- GitHub rulesets integration — wire
apm audit --ciinto branch protection
Get Started
macOS with Homebrew
brew install apm
No custom tap is required. Homebrew manages installation and updates:
use brew upgrade apm, not apm self-update.
Linux / macOS without Homebrew
curl -sSL https://aka.ms/apm-unix | sh
Windows
irm https://aka.ms/apm-windows | iex
Native release binaries are published for macOS, Linux, and Windows x86_64.
For standalone installations, apm self-update reuses the matching platform installer.
You do not need Homebrew to use APM.
Other install methods: pip, WinGet, and Scoop
Linux / macOS
# pip (Python 3.10+)
pip install apm-cli
Windows
# WinGet
winget install --id Microsoft.APM --exact --source winget
# Scoop
scoop bucket add apm https://github.com/microsoft/scoop-apm
scoop install apm
# pip
pip install apm-cli
Already using the Microsoft Homebrew tap? See the migration guide.
Then start adding packages:
apm install microsoft/apm-sample-package#v1.0.0
Or install from a marketplace:
apm marketplace add github/awesome-copilot
apm install azure-cloud-development@awesome-copilot
Or add an MCP server (wired into Copilot, Claude, Cursor, Codex, OpenCode, Gemini, Windsurf, and Kiro):
apm install --mcp io.github.github/github-mcp-server --transport http # connects over HTTPS
See the Getting Started guide for the full walkthrough.
Works with agentrc
agentrc analyzes your codebase and generates tailored agent instructions — architecture, conventions, build commands — from real code, not templates.
Use agentrc to author high-quality instructions, then package them with APM to share across your org. The .instructions.md format is shared by both tools — no conversion needed when moving instructions into APM packages.
Community
Created by @danielmeppiel. Maintained by @danielmeppiel and @sergio-sisternes-epam.
- v0.29 Roadmap
- Discussions
- Contributing
- AI Native Development guide — a practical learning path for AI-native development
Built on open standards: AGENTS.md · Agent Skills · MCP
Trademarks
This project may contain trademarks or logos for projects, products, or services. Authorized use of Microsoft trademarks or logos is subject to and must follow Microsoft's Trademark & Brand Guidelines. Use of Microsoft trademarks or logos in modified versions of this project must not cause confusion or imply Microsoft sponsorship. Any use of third-party trademarks or logos are subject to those third-party's policies.
Files in the repo
- .agents
- .apm
- .github
- .vscode
- build
- devcontainer
- docs
- packages
- scripts
- src
- templates
- tests
- .editorconfig
- .gitattributes
- .gitignore
- .gitmodules
- .pre-commit-config.yaml
- apm.lock.yaml
- apm.yml
- AUTHORS
- CHANGELOG.md
- CODE_OF_CONDUCT.md
- CONFORMANCE.json
- CONFORMANCE.md
- CONTRIBUTING.md
- install.ps1
- install.sh
- LICENSE
- Makefile
- MANIFESTO.md
- NOTICE
- PRINCIPLES.md
- pyproject.toml
- README.md
- SECURITY.md
- SUPPORT.md
- uv.lock
Discussion (0)
Ask about usage, or say what you built with itSign in to join the discussion.
No comments yet. Be the first to say what this is good for.
More tools
The best-benchmarked open-source AI memory system. And it's free.
Orca is the ADE for working with a fleet of parallel agents. Run any coding agent with your own subscription. Available on desktop, mobile and remote runtime.

A cross-platform desktop All-in-One assistant for Claude Code, Codex, OpenCode, OpenClaw, Grok Build & Hermes Agent. Only official website: ccswitch.io
Never stop coding. Free MIT AI gateway: one endpoint, 352 providers (150+ free), 1200+ models Kimi, Claude, GPT, Gemini, GLM, DeepSeek, MiniMax. Works with Claude Code, Codex, Cursor, OpenCode, Cline & Copilot. Quota-aware auto-fallback, RTK+Caveman compression saves 15-95% tokens, MCP/A2A, Desktop/PWA. Built by 550+ contributors
Compress tool outputs, logs, files, and RAG chunks before they reach the LLM. 20% fewer tokens for coding agents, 60-95% fewer tokens for JSON, same answers. Library, proxy, MCP server.