{"_id":"@0x_dhruv/dpack","_rev":"3-f4397a06a904187d714593766843f48e","name":"@0x_dhruv/dpack","dist-tags":{"latest":"0.1.2"},"versions":{"0.1.0":{"name":"@0x_dhruv/dpack","version":"0.1.0","keywords":["agent-skills","cli","codex","cursor"],"license":"MIT","_id":"@0x_dhruv/dpack@0.1.0","maintainers":[{"name":"0x_dhruv","email":"dhruvluthra1@gmail.com"}],"homepage":"https://github.com/dhruvluthra/dpack#readme","bugs":{"url":"https://github.com/dhruvluthra/dpack/issues"},"bin":{"dpack":"dist/cli.js"},"dist":{"shasum":"96f8540529bc79065f40fe78a74d5ea40af88c10","tarball":"https://registry.npmjs.org/@0x_dhruv/dpack/-/dpack-0.1.0.tgz","fileCount":79,"integrity":"sha512-qOSSgUHC+soFSZQ8HIBSGOnmEwFCoGcoCe0BYHLfWkXs3dqMbLXLJDVP2BIWcbAVlufBZeOn0bBZhrp/hdxV6A==","signatures":[{"sig":"MEQCIH0KLnuU3Yrch2HszkNSPttpc1vwp/nuF/taHx7iMuPtAiA1ifmm0eZYbg3qzet1y4XLqK0aauPaRMKVvZOGKJVUdw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":89897},"type":"module","engines":{"node":">=20"},"gitHead":"f3cf9f9cf7f74bb469afba166b1179990766a131","scripts":{"test":"vitest run","build":"tsc -p tsconfig.json","check":"tsc -p tsconfig.json --noEmit","test:watch":"vitest"},"_npmUser":{"name":"0x_dhruv","email":"dhruvluthra1@gmail.com"},"repository":{"url":"git+https://github.com/dhruvluthra/dpack.git","type":"git"},"_npmVersion":"10.9.4","description":"A lightweight npm-backed package manager for Agent Skills.","directories":{},"_nodeVersion":"22.21.1","dependencies":{"tar":"^7.4.3","zod":"^4.1.5","commander":"^14.0.0","gray-matter":"^4.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.2.4","typescript":"^5.9.2","@types/node":"^24.3.0"},"_npmOperationalInternal":{"tmp":"tmp/dpack_0.1.0_1787797084300_0.8582393010042333","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@0x_dhruv/dpack","version":"0.1.1","keywords":["agent-skills","cli","codex","cursor"],"license":"MIT","_id":"@0x_dhruv/dpack@0.1.1","maintainers":[{"name":"0x_dhruv","email":"dhruvluthra1@gmail.com"}],"homepage":"https://github.com/dhruvluthra/dpack#readme","bugs":{"url":"https://github.com/dhruvluthra/dpack/issues"},"bin":{"dpack":"dist/cli.js"},"dist":{"shasum":"2e204eb280ba8905288da83886ce468f8e2e9552","tarball":"https://registry.npmjs.org/@0x_dhruv/dpack/-/dpack-0.1.1.tgz","fileCount":79,"integrity":"sha512-k7K8cDQdddCEAbt92eIC5kS5bjUs30xhZ3GJoUnKNCwmlgUFjMnvy30+SFKtzWRmL/vHB1xw7EXThU1B1RXr9w==","signatures":[{"sig":"MEYCIQDecfVBFeWGeDGE3/LXmQW8YnI3vZIjIIYjCA6MjGNp7gIhAJyjQHp2rTV+nwFY0KurMZ+IV6a7bv8hde5vDxmRIu0W","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":89898},"type":"module","engines":{"node":">=20"},"gitHead":"68c1709ff727815c50764dcee841a97fdf7ba18f","scripts":{"test":"vitest run","build":"tsc -p tsconfig.json","check":"tsc -p tsconfig.json --noEmit","test:watch":"vitest"},"_npmUser":{"name":"0x_dhruv","email":"dhruvluthra1@gmail.com"},"repository":{"url":"git+https://github.com/dhruvluthra/dpack.git","type":"git"},"_npmVersion":"10.9.4","description":"A lightweight npm-backed package manager for Agent Skills.","directories":{},"_nodeVersion":"22.21.1","dependencies":{"tar":"^7.4.3","zod":"^4.1.5","commander":"^14.0.0","gray-matter":"^4.0.3"},"_hasShrinkwrap":false,"devDependencies":{"vitest":"^3.2.4","typescript":"^5.9.2","@types/node":"^24.13.3"},"_npmOperationalInternal":{"tmp":"tmp/dpack_0.1.1_1787879042375_0.712412481295396","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@0x_dhruv/dpack","version":"0.1.2","description":"A lightweight npm-backed package manager for Agent Skills.","type":"module","bin":{"dpack":"dist/cli.js"},"scripts":{"build":"tsc -p tsconfig.json","check":"tsc -p tsconfig.json --noEmit","test":"vitest run","test:watch":"vitest"},"engines":{"node":">=20"},"keywords":["agent-skills","cli","codex","cursor"],"license":"MIT","repository":{"type":"git","url":"git+https://github.com/dhruvluthra/dpack.git"},"dependencies":{"commander":"^14.0.0","gray-matter":"^4.0.3","tar":"^7.4.3","zod":"^4.1.5"},"devDependencies":{"@types/node":"^24.13.3","typescript":"^5.9.2","vitest":"^3.2.4"},"_id":"@0x_dhruv/dpack@0.1.2","gitHead":"8129705a892be400b6bcb8c38743977f1afd10a3","bugs":{"url":"https://github.com/dhruvluthra/dpack/issues"},"homepage":"https://github.com/dhruvluthra/dpack#readme","_nodeVersion":"22.21.1","_npmVersion":"10.9.4","dist":{"integrity":"sha512-M0gtGjaILYC4hMKgt9CHWzoOTSvf9m73Ork/WqO3HsxhyDG6q4aeCaKWyxtm9ewNNrCxkjgFh+C7VKHgTCihdw==","shasum":"83605d53df54a99d694dcef6e316beba0399797f","tarball":"https://registry.npmjs.org/@0x_dhruv/dpack/-/dpack-0.1.2.tgz","fileCount":79,"unpackedSize":90505,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIHM7JAApv6E6heK6q5QstE4bYCklZjRmTz4tONGEx8mRAiA4a/wKUIsN3ysadu5KVz2DHPYkdMWDw/NjA83Fd7ujIQ=="}]},"_npmUser":{"name":"0x_dhruv","email":"dhruvluthra1@gmail.com"},"directories":{},"maintainers":[{"name":"0x_dhruv","email":"dhruvluthra1@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/dpack_0.1.2_1787881401092_0.6200630197306709"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-27T02:18:04.102Z","modified":"2026-08-28T01:43:21.387Z","0.1.0":"2026-08-27T02:18:04.455Z","0.1.1":"2026-08-28T01:04:02.520Z","0.1.2":"2026-08-28T01:43:21.252Z"},"bugs":{"url":"https://github.com/dhruvluthra/dpack/issues"},"license":"MIT","homepage":"https://github.com/dhruvluthra/dpack#readme","keywords":["agent-skills","cli","codex","cursor"],"repository":{"type":"git","url":"git+https://github.com/dhruvluthra/dpack.git"},"description":"A lightweight npm-backed package manager for Agent Skills.","maintainers":[{"name":"0x_dhruv","email":"dhruvluthra1@gmail.com"}],"readme":"# dpack\n\n`dpack` is a lightweight package manager for [Agent Skills](https://agentskills.io/). npm handles distribution, the Agent Skills specification defines package contents, and `.agents/skills/` provides a filesystem convention that compatible coding agents can discover.\n\n`dpack` does not provide an agent runtime, registry, marketplace, or proprietary skill format. It copies standard skill directories without transforming them.\n\n## Installation\n\nRequires Node.js 20 or newer and an `npm` executable on `PATH`.\n\n```bash\nnpm install -g @0x_dhruv/dpack\n```\n\nFor local development:\n\n```bash\nnpm install\nnpm run build\nnode dist/cli.js --help\n```\n\n## Commands\n\nCreate a new publishable skill package:\n\n```bash\ndpack init financial-research\n```\n\nValidate a skill directory:\n\n```bash\ndpack validate ./financial-research\n```\n\nInstall from npm, a pinned npm version, or a local directory:\n\n```bash\ndpack add @foo/financial-research\ndpack add @foo/financial-research@1.2.0\ndpack add ./financial-research\n```\n\nList and remove project skills:\n\n```bash\ndpack list\ndpack remove financial-research\n```\n\nUse `-g` for skills shared through your home directory:\n\n```bash\ndpack add -g @foo/financial-research\ndpack list -g\ndpack remove -g financial-research\n```\n\nRun `dpack <command> --help` for command-specific help.\n\n## Installation locations\n\nProject-scoped skills are installed to:\n\n```text\n<project-root>/.agents/skills/<skill-name>/\n```\n\n`dpack` walks upward from the current directory and prefers an enclosing `.git` marker, including the `.git` files used by Git worktrees. If no Git marker exists, it uses the nearest `package.json`. If neither exists, it uses the current directory and reports that fallback.\n\nGlobal skills are installed to:\n\n```text\n~/.agents/skills/<skill-name>/\n```\n\nPackage-management metadata is recorded in `.agents/skills.lock` for both scopes. The lockfile tracks source and resolved npm metadata, but installed skills are discovered from the filesystem rather than solely from the lockfile. Manually placed skills therefore appear in `dpack list` too.\n\nAn existing destination is never silently overwritten. V0 intentionally has no `--force` or update command.\n\n## Skill package format\n\nA skill is a directory containing a `SKILL.md` file with YAML frontmatter and Markdown instructions:\n\n```text\nmy-skill/\n├── package.json\n├── SKILL.md\n├── scripts/\n├── references/\n├── assets/\n└── agents/\n```\n\nOnly `SKILL.md` is required by the Agent Skills format. Its frontmatter must contain a valid `name` and `description`:\n\n```markdown\n---\nname: my-skill\ndescription: Explain what the skill does and when an agent should use it.\nlicense: MIT\nmetadata:\n  author: example\n---\n\n# My Skill\n\nAdd instructions here.\n```\n\nNames must be 1–64 characters containing lowercase letters, numbers, and single hyphens. Descriptions must be nonempty and no longer than 1,024 characters. Known optional values are type-checked, while unknown frontmatter fields and vendor-specific directories are preserved without interpretation.\n\nThe npm package name does not need to match the skill name. A package such as `@foo/research-tools` may contain a skill named `financial-research`; installation uses the name from `SKILL.md`.\n\nSee [`examples/hello-world`](examples/hello-world) for a complete minimal package.\n\n## Publishing a skill\n\nAfter editing the generated files, validate and publish with npm:\n\n```bash\ndpack validate ./financial-research\ncd financial-research\nnpm publish\n```\n\nScoped packages work with normal npm publication rules. Edit the generated `package.json` name to a scope such as `@your-scope/financial-research` when needed; the `SKILL.md` name remains `financial-research`.\n\n## Security model\n\nSkill packages are untrusted input. During installation, `dpack`:\n\n- downloads packages with `npm pack --ignore-scripts` instead of `npm install`;\n- invokes npm with an argument array and no shell interpolation;\n- does not execute files from a skill's `scripts/` directory;\n- validates every tar entry before extraction and rejects traversal, links, devices, and other unsafe entry types;\n- rejects symbolic links in local skill directories;\n- stages copies before atomically moving them into place;\n- validates direct-child paths before removal; and\n- cleans temporary download and extraction directories on success or failure.\n\nThese checks make installation safer, but they do not audit the instructions or executable code for what a compatible agent may do after installation. Review third-party skills before using them.\n\n## Architecture\n\n```text\nnpm package or local directory\n              ↓\n            dpack\n              ↓\n .agents/skills/<skill-name>\n              ↓\n Codex, Cursor, and other compatible clients\n```\n\nThe canonical skill metadata remains in `SKILL.md`. `dpack` never requires `skill.json`, `askill.json`, or another per-skill manifest. `.agents/skills.lock` contains only package-management provenance.\n\n## Development\n\n```bash\nnpm run check\nnpm test\nnpm run build\nnpm pack --dry-run --ignore-scripts\n```\n\nThe test suite covers parsing, project discovery, staged local installation, npm subprocess arguments, archive security, lockfile updates and rollback, global operations, CLI output, and removal traversal.\n\n## V0 limitations\n\n- npm is the only remote transport.\n- Installs are snapshots, not symbolic links.\n- There is no update, restore-from-lock, deduplication, or `--force` workflow.\n- Symbolic and hard links inside packages are unsupported.\n- `dpack list` reports invalid skills but does not repair them.\n\n## License\n\nMIT\n","readmeFilename":"README.md"}