Files
holocron/plugins/kyberforge/skills/apm-workflow/SKILL.md
Defame1297 394052ff66 docs(kyberforge): fix remaining PR #91 review findings, add apm install routing
Re-review (comment 24) of fix commit e16c3dc found six new issues, mostly
introduced by that fix commit itself: a dangling reference to a Hard Rule
bullet the same commit deleted (apm-orchestrate.md/.agent.md Process step
2 still named "secret indirection"), and an ADR-0015 Decision bullet that
claimed "this ADR does not update CONTEXT.md" while the same commit had
just added a forward-pointer sentence to CONTEXT.md's Plugin/Plugin
marketplace entries. Both reworded to match what actually happened.

apm-install's APM_INSTALL_DIR escape-hatch example dropped the curl pipe
entirely (`APM_INSTALL_DIR=... sh` with nothing piped into it) — fixed in
both apm-install/SKILL.md and the installation.md research doc, verified
against the upstream Microsoft APM docs via Context7.

Neither apm-workflow nor apm-orchestrate routed to plain `apm install
[PACKAGE_REF]`, the CLI command that actually resolves/fetches
dependencies declared in apm.yml — apm-install only bootstraps the apm
binary/runtime, not per-package deps. Added a 5th "install" dispatch
action to apm-workflow (new references/install.md, SKILL.md table row,
README usage/files sync, sources.md provenance entry) and a matching
"install" operation group on apm-orchestrate so it can route there.

configure.md's apm.yml schema block was also missing the "legacy singular
`target:` CSV form is still accepted" caveat its sibling research doc
documents for the same field — added for consistency.

The sixth finding (paired .md/.agent.md Output-contract disagreement) was
checked against git-orchestrate and gitea-orchestrate's existing pairs and
found to match established repo convention (JSON schema in .md, prose
summary without the enum in .agent.md) — left unchanged as a false
positive rather than "fixed."

kyberforge bumped 1.3.0 -> 1.3.1 via agent-author's normal improve flow.

Refs: #91

Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_0186ERbyACLRuRxPRnqwpa4m
2026-08-11 11:09:43 +00:00

3.6 KiB

name, description, metadata
name description metadata
apm-workflow Use when the user wants to author or edit an apm.yml manifest (dependencies, scripts, compilation, policy, registries), scaffold a new apm package or marketplace (apm plugin init, apm marketplace init/package add), register a marketplace as a consumer, compile/pack/publish an apm package for distribution, or validate/audit apm.yml and installed content (apm audit, apm marketplace check) — even if the user doesn't say "apm" explicitly, e.g. "set up the package manifest", "scaffold this as an apm package", "build the distributable", "check this passes CI". Do not use for installing the apm binary itself or setting up an agent runtime — use apm-install for those.
category source_keys
apm
context7-microsoft-apm

Gotchas

  • apm.yml's type: field (instructions, skill, hybrid, prompts) constrains what .apm/ may contain — set it before scaffolding content, not after. Changing it later doesn't retroactively validate what's already on disk.
  • includes: auto publishes the authoritative local layout as-is. Anything narrower needs an explicit repo-path list — don't assume auto means "scoped down to what's relevant."
  • apm marketplace add (registering a marketplace as a consumer, pointing at someone else's catalog) and apm marketplace package add (registering a local package into a marketplace you're building) are opposite directions of the same command family — don't conflate them.
  • apm pack is the same command that both bundles a distributable artifact and emits .claude-plugin/marketplace.json as one of its compile targets — regenerating the Claude Code-native manifest isn't a separate step from packing.
  • MCP server secrets (headers, env vars) inside apm.yml must use ${VAR} indirection, never literal values, so they're resolved at install/runtime and never committed to the manifest.
  • apm experimental enable registries must run before any registry.* config takes effect. Declaring a registries: block or running apm config set registry.* without it silently does nothing — no error, no warning.
  • Plain apm audit and apm audit --ci check different things: plain apm audit scans deployed files for hidden Unicode only; --ci additionally runs lockfile-consistency checks, install-replay drift detection, and org policy checks. A clean plain apm audit is not a CI-equivalent pass.

Step 1 — Dispatch

Invocation Action Reference
/apm-workflow configure Author/edit apm.yml; scaffold a new package (apm plugin init) references/configure.md
/apm-workflow install Resolve/fetch dependencies declared in apm.yml (apm install, apm install [PACKAGE_REF]) references/install.md
/apm-workflow marketplace Build a marketplace, register packages into it, or register a marketplace as a consumer (apm marketplace init/check/package add/add) references/marketplace.md
/apm-workflow compile Generate per-target output, bundle, or publish (apm compile, apm pack, apm publish) references/compile.md
/apm-workflow audit Validate integrity/policy, wire a CI gate, or check marketplace refs resolve (apm audit, apm audit --ci, apm marketplace check) references/audit.md

Read only the reference file matching the requested action — each is self-contained for its concern.

Step 2 — Execute

Follow the matched reference file's instructions. Report back which apm command(s) were run (or drafted, if the user asked for a plan rather than execution) and their outcome.