Claude Code's (and Copilot's) native plugin installer has zero awareness of .apm/ nesting -- it convention-scans only flat skills/, agents/, commands/, hooks.json at each plugin's root. Confirmed via strings on the installed claude binary and live installs of git@holocron/gitea@holocron/kyberforge@ holocron, all reporting Skills(0) Agents(0) Hooks(0) post ADR-0015's apm conversion. Root cause (apm_cli/core/plugin_manifest.py): apm's plugin.json compiler deliberately strips skills/agents/commands keys, assuming the host already auto-discovers those convention directories -- it has no model of .apm/ being host-visible at all. Separately, apm's own bundle exporter (apm_cli/bundle/plugin_exporter.py, behind `apm pack --format plugin`) implements the correct .apm/ -> flat mapping, but only ever targeted build/<name>-<version>/, a path nothing in marketplace.json's source: points at. scripts/sync-plugin-content.sh wraps that bundle exporter and copies its agents/, skills/, commands/, instructions/, extensions/, and merged hooks.json back into each plugin's own root as a second tracked compiled-output category -- same governance status as .claude-plugin/plugin.json: generated from .apm/, never hand-edited. tests/ subdirectories are excluded from the mirror (dev fixtures, not host-visible runtime content; several hardcode a relative repo-root walk-up sized for the .apm/-nested depth, which breaks when duplicated one level shallower). Applied for real across all 6 plugins and verified two ways: `claude plugin validate --strict` passes on every real plugin directory, and a live `claude --plugin-dir <path> -p "list skills/agents"` behavioral test confirms content is now actually discovered. Also, from the same issue #90 review round: - scripts/check-manifests.sh pointed at each plugin's root-level plugin.json (checking skills/hooks/mcpServers/agents pointer fields) -- that file was a stale near-duplicate of .claude-plugin/plugin.json nothing else read or wrote, now deleted across all 6 plugins. check-manifests.sh is rewritten to validate .claude-plugin/plugin.json instead, and drops the pointer-field checks entirely (nothing to check -- those fields are correctly absent by design). Content-presence drift is now check-plugin-content-sync's job, a new pre-push hook wired in .pre-commit-config.yaml. docs/adr/0017 records the root cause and decision in full, including two rejected alternatives (patching plugin.json's path fields directly -- apm's compiler strips them on every run; pointing marketplace.json at apm pack's build/ output -- a version-suffixed non-source directory nothing can install from without an extra build step). ADR-0015 and CONTEXT.md are updated to point at it. Refs: #90
3.9 KiB
3.9 KiB
name, description, metadata
| name | description | metadata | |||||
|---|---|---|---|---|---|---|---|
| apm-workflow | Use when the user wants to author or edit an apm.yml manifest (dependencies, scripts, compilation, policy, registries), scaffold a new apm package or marketplace (apm plugin init, apm marketplace init/package add), install or resolve dependencies declared in apm.yml (apm install, apm install [PACKAGE_REF]), register a marketplace as a consumer, compile/pack/publish an apm package for distribution, or validate/audit apm.yml and installed content (apm audit, apm marketplace check) — even if the user doesn't say "apm" explicitly, e.g. "set up the package manifest", "scaffold this as an apm package", "install my apm dependencies", "resolve apm.yml deps", "build the distributable", "check this passes CI". Do not use for installing the apm binary itself or setting up an agent runtime — use apm-install for those. |
|
Gotchas
apm.yml'stype:field (instructions,skill,hybrid,prompts) constrains what.apm/may contain — set it before scaffolding content, not after. Changing it later doesn't retroactively validate what's already on disk.includes: autopublishes the authoritative local layout as-is. Anything narrower needs an explicit repo-path list — don't assumeautomeans "scoped down to what's relevant." Note:autostill excludes generic root-level passthrough files (README.md, docs/, sources.md, config files) from theapm packdistribution bundle — seereferences/compile.md.apm marketplace add(registering a marketplace as a consumer, pointing at someone else's catalog) andapm marketplace package add(registering a package by remote reference —owner/repo, host URL, or full URL — into a marketplace you're building) are opposite directions of the same command family — don't conflate them.package adddoes NOT accept local paths; a local package is registered by hand-editingapm.yml'smarketplace.packages[]directly — seereferences/marketplace.md.- MCP server secrets (headers, env vars) inside
apm.ymlmust use${VAR}indirection, never literal values, so they're resolved at install/runtime and never committed to the manifest. apm experimental enable registriesmust run before anyregistry.*config takes effect. Declaring aregistries:block or runningapm config set registry.*without it silently does nothing — no error, no warning.- Plain
apm auditandapm audit --cicheck different things: plainapm auditscans deployed files for hidden Unicode only;--ciadditionally runs lockfile-consistency checks, install-replay drift detection, and org policy checks. A clean plainapm auditis not a CI-equivalent pass.
Step 1 — Dispatch
| Invocation | Action | Reference |
|---|---|---|
/apm-workflow configure |
Author/edit apm.yml; scaffold a new package (apm plugin init) |
references/configure.md |
/apm-workflow install |
Resolve/fetch dependencies declared in apm.yml (apm install, apm install [PACKAGE_REF]) |
references/install.md |
/apm-workflow marketplace |
Build a marketplace, register packages into it (local: hand-edit apm.yml; remote: apm marketplace package add), or register a marketplace as a consumer (apm marketplace init/check/package add/add) |
references/marketplace.md |
/apm-workflow compile |
Generate per-target output, bundle, or publish (apm compile, apm pack, apm publish) |
references/compile.md |
/apm-workflow audit |
Validate integrity/policy or wire a CI gate (apm audit, apm audit --ci) |
references/audit.md |
Read only the reference file matching the requested action — each is self-contained for its concern.
Step 2 — Execute
Follow the matched reference file's instructions. Report back which apm command(s) were run (or drafted, if the user asked for a plan rather than execution) and their outcome.