apm — security grade SAFE, quality 60/100

Security audit verdict: SAFE · quality 60/100

No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →

by microsoft · Codex Skill · ★ 3.9k

Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h

🔒 Is apm safe to install? View the security audit →

About apm

APM – Agent Package Manager An open-source, community-driven dependency manager for AI agents. Think , , or — but for AI agent configuration. GitHub Copilot · Claude Code Documentation · Quick Start · CLI Reference Why APM AI coding agents need context to be useful — standards, prompts, skills, plugins — but today every developer sets this up manually. Nothing is portable nor reproducible. There's no manifest for it. APM fixes this. Declare your project's agentic dependencies once in , and every developer who clones your repo gets a fully configured agent setup in seconds — with transitive dependency resolution, just like npm or pip. Highlights One manifest for everything —

ai-agentsclaude-codecodex-clicontext-engineeringgithub-copilotpackage-managerprompt-engineering

Quick Facts

Stars3,878
Forks372
LanguagePython
CategoryCodex Skill
LicenseMIT
Quality Score60.2926447113647/100
Open Issues230
Last Updated2026-09-22
Created2025-09-18
Platformsclaude-code, cli, codex, node, python, rust
Est. Tokens~14k

Compatible Skills

These tools work well together with apm for enhanced workflows:

  • mcpm.sh — semantic(0.37)+complementary+rare_topics+same_lang+similar_pop+shared_platform (63%)
  • agent-resources — semantic(0.47)+complementary+same_lang+similar_pop+shared_platform (61%)
  • craftdesk — semantic(0.47)+complementary+rare_topics+similar_pop+shared_platform (56%)
  • kindly-web-search-mcp-server — semantic(0.16)+complementary+same_lang+similar_pop+shared_platform (56%)
  • claude-code-plugins-plus-skills — semantic(0.23)+complementary+same_lang+similar_pop+shared_platform (53%)

apm alternative? Top 6 similar tools

Looking for a apm alternative? If you're comparing apm with other codex skill tools, these 6 projects are the closest alternatives on Agent Skills Hub — ranked by topic overlap, star count, and community traction.

  • quint-code by m0n0x41d · ⭐ 1.3k

    Engineering decisions engine that know when they're stale. Frame, compare, decide — with evidence decay and p

  • claude-scholar by Galaxy-Dawn · ⭐ 5.2k

    Semi-automated research assistant for academic research and software development. Supports Claude Code, Codex

  • ralph-orchestrator by mikeyobrien · ⭐ 3.1k

    An improved implementation of the Ralph Wiggum technique for autonomous AI agent orchestration

  • vibe-coding-prompt-template by KhazP · ⭐ 3.1k

    Templates and workflow for generating PRDs, Tech Designs, and MVP and more using LLMs for AI IDEs

  • pro-workflow by rohitg00 · ⭐ 2.8k

    Claude Code learns from your corrections: self-correcting memory that compounds over 50+ sessions. Context eng

  • Claude-Code-Everything-You-Need-to-Know by wesammustafa · ⭐ 2.6k

    A practical Claude Code guide with clear mental models and copy-paste examples — setup, prompt engineering, sl

More Codex Skill Tools

Explore other popular codex skill tools:

View all Codex Skill tools →

Popular Python Agent Tools

Frequently Asked Questions

What is apm?

apm is Agent Package Manager. It is categorized as a Codex Skill with 3.9k GitHub stars.

What programming language is apm written in?

apm is primarily written in Python. It covers topics such as ai-agents, claude-code, codex-cli.

How do I install or use apm?

You can find installation instructions and usage details in the apm GitHub repository at github.com/microsoft/apm. The project has 3.9k stars and 372 forks, indicating an active community.

What license does apm use?

apm is released under the MIT license, making it free to use and modify according to the license terms.

What are the best alternatives to apm?

The top alternatives to apm on Agent Skills Hub include quint-code, claude-scholar, ralph-orchestrator. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.

How this security grade is produced

Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.

The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.

Sources & who's responsible:

View on GitHub → Browse Codex Skill tools