Files
holocron/plugins/kyberforge
Defame1297 ae178a95a2 fix(kyberforge): detect a single stale package at SessionStart
apm prints "1 outdated dependency found" in the singular when exactly one
package is behind (apm_cli/commands/outdated.py). check-apm-current.sh
matched only "outdated dependencies found", so one stale package was
invisible: the hook exited 0 silently and no refresh ran. With six
packages merging independently, one-behind is the ordinary case, so the
freshness mechanism failed most often in the situation it exists for.

Three further defects in the same hook:

- The host timeout was below the script's own budget. hooks.json declared
  320s while the script allows `timeout 60` plus `timeout 300` = 360s, so
  a slow remote let the host kill the hook mid-update and leave
  .claude/skills/ half-deployed with nothing emitted. Now 380. A test
  asserts the invariant rather than the literal: it sums every `timeout N`
  parsed out of the script and requires hooks.json to exceed it, so
  changing either side alone fails.

- The lockfile guard was cwd-relative, so a session opened in a
  subdirectory no-opped silently and ran both apm calls against the wrong
  directory. Now anchored on CLAUDE_PROJECT_DIR, falling back to the cwd
  so the hook stays inert under a host that does not set it.

- Every assertion mocked apm, so the suite was green over code that could
  not detect its own most common trigger. That blind spot is what hid the
  singular/plural bug, and it is the same shape as the deleted post-push
  tests. The suite now stages a genuinely outdated dependency against a
  local git remote — offline, via url.<path>.insteadOf, so the
  pass-under-unshare property survives — runs the real `apm outdated`, and
  replays its output through the real hook. Reverting the grep to
  plural-only fails it.

23 -> 35 assertions. Each fix mutation-tested individually. kyberforge
stays at 1.5.0: it is untagged, so this changes what 1.5.0 ships rather
than superseding it, and executables.allow needs no edit.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
Claude-Session: https://claude.ai/code/session_01X7GvKuJfy2WrdBmUttV4DT
2026-08-14 18:31:30 +00:00
..

kyberforge

Skills and agents for creating, maintaining, and managing a Claude Code / Copilot CLI plugin marketplace.

Install

Claude Code:

claude plugin marketplace add <owner>/<repo>
claude plugin install kyberforge@<marketplace-name>

GitHub Copilot CLI:

copilot plugin marketplace add <owner>/<repo>
copilot plugin install kyberforge

Local (development):

# Claude Code
claude --plugin-dir ./plugins/kyberforge

# GitHub Copilot CLI
copilot plugin install ./plugins/kyberforge

Contents

Authoring source lives in .apm/. The skills/, agents/, and hooks/hooks.json paths below are the generated mirror that plugin hosts actually scan — produced by scripts/sync-plugin-content.sh, never hand-edited (ADR-0017).

Component Path Description
Skills .apm/skills/ → skills/ Slash commands available after install
Agents .apm/agents/*.agent.md → agents/ Role-based agents; one vendor-neutral .agent.md per agent, copied verbatim to both targets (ADR-0016)
Hooks .apm/hooks/ → hooks/hooks.json Event-triggered automation — read by Claude Code only, see below
MCP servers .mcp.json Model Context Protocol server definitions (hand-authored at the plugin root)

Hooks are Claude Code-only in practice. Claude Code convention-scans hooks/hooks.json at the plugin root, so that file is live. Copilot CLI has no default hooks path — agents and skills default to agents/ and skills/, but hooks defaults to nothing (docs/research/docs/github-copilot-plugins/configuration.md:47), so Copilot reads hooks only via an explicit "hooks": "hooks.json" pointer in plugin.json (docs/research/docs/github-copilot-plugins/examples.md:49). apm's manifest compiler strips pointer fields from every manifest it generates, so neither .claude-plugin/plugin.json nor .github/plugin/plugin.json carries one, and re-injecting it is the option ADR-0017 explicitly rejected. Copilot therefore loads no hooks from this plugin — and did not load them from the old root-level hooks.json either. The Copilot half of this row is aspirational, not current behaviour.

Skills

Skill Description
forge Grill an unclassified "I want to add something" request, decide whether it's a skill, agent, plugin, or marketplace entry, then route to the matching author skill
skill-author Create or improve a skill from scratch, audit findings, or inline feedback
skill-audit Audit a skill directory against the agentskills.io spec and produce a findings report
agent-author Author an agent definition file
agent-audit Audit an agent definition across structure, provider safety, description and body quality, and provenance; produces a findings report
apm-install Install or upgrade the apm CLI and set up the agent runtimes it drives (Copilot CLI, Codex, Gemini, generic llm)
apm-workflow Author apm.yml, scaffold an apm package/marketplace, install dependencies, and compile/pack/publish/audit apm content

Pre-commit tooling (pc-author, pc-run) lives in the git plugin, not here.

Author

Defame1297