Apm UsageSAFE
Agent Package Manager
Overview
Agent Package Manager
2ea90c57fbfcOBSERVED · 2026-10-08Install
Commands as the repository documents them. They are shown, not run.
git clone <repo-url>
Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned | |
| codex | mentioned | |
| copilot | mentioned | |
| cursor | mentioned | |
| gemini-cli | mentioned | |
| openclaw | mentioned | |
| windsurf | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
--- name: apm-usage description: > Activate when the user asks about APM (Agent Package Manager): installing, configuring, authoring, or troubleshooting AI-agent packages, dependencies, compilation, MCP servers, policy, or any `apm` CLI command. --- # APM Usage APM (Agent Package Manager) is the open-source package manager for AI coding agents. It lets teams install, share, and govern reusable instructions, prompts, agents, skills, and MCP server configurations across projects. ## When to activate - User mentions `apm` or "Agent Package Manager" - Questions about installing or managing AI-agent packages - Setting up instructions, prompts, agents, skills, or chatmodes - Configuring MCP servers through apm.yml - Authentication for private repos (GitHub, ADO, GHES, Artifactory) - Policy enforcement or `apm audit` - Package authoring or publishing - Compiling agent context (`apm compile`) - Troubleshooting apm errors ## Key rules - **Commit these files:** apm.yml, apm.lock.yaml, .apm/, deployed harness directories including .grok/, and AGENTS.md - **Never commit:** apm_modules/ (add to .gitignore) - **Team sync:** after `git clone`, run `apm install` to restore dependencies - **Update deps:** `apm install --update` refreshes to latest refs - **Pin versions:** use tags (`#v1.0.0`) in production, branches for development - **ASCII only:** all CLI output and source must stay within printable ASCII ## Reference For detailed guidance, see the following resources: - [Installation](./installation.md) -- install and update APM - [Workflow](./workflow.md) -- core workflow, apm.yml format, what to commit - [Commands](./commands.md) -- full CLI command reference - [Dependencies](./dependencies.md) -- all dependency formats and version pinning - [Authentication](./authentication.md) -- token setup for private repos - [Governance](./governance.md) -- policy engine and audit checks - [Package Authoring](./package-authoring.md) -- creating APM packages - [Troubleshooting](./troubleshooting.md) -- common errors and fixes
Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (5)
if unrestricted access is intentional; otherwise do not use the generated
curl -sSL https://aka.ms/apm-unix | sh
curl -sSL https://aka.ms/apm-unix | sh -s -- @v1.2.3
curl -sSL https://aka.ms/apm-unix | sh -s -- --prefix "$HOME/.local"
curl -sSL "$APM_INSTALLER_BASE_URL/install.sh" | sh
Gates applied: no_behavioural_pass.
2ea90c57fbfcfull audit observations/trust-audit/skill/microsoft__apm-usage.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 2ea90c57fbfc | SAFE | B | 89 | first audit |
Questions
What does the Apm Usage skill do?
Agent Package Manager
Is Apm Usage safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Apm Usage access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Apm Usage work with?
Its documentation mentions claude-code, codex, copilot, cursor, gemini-cli, openclaw and windsurf. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (2ea90c57fbfc), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.