{"_id":"@amajumdar2249/agentpm","_rev":"3-b278d90b930f8ac58cb83605d64a2e7c","name":"@amajumdar2249/agentpm","dist-tags":{"latest":"1.3.0"},"versions":{"1.1.0":{"name":"@amajumdar2249/agentpm","version":"1.1.0","keywords":["ai-agent","package-manager","skills","prompt-injection","security","mcp","claude-code","cursor","agentpm","cli"],"author":{"name":"amajumdar2249"},"license":"MIT","_id":"@amajumdar2249/agentpm@1.1.0","maintainers":[{"name":"amajumdar2249","email":"amajumdar2249@gmail.com"}],"homepage":"https://github.com/amajumdar2249/agentpm","bugs":{"url":"https://github.com/amajumdar2249/agentpm/issues"},"bin":{"agentpm":"dist/index.js","agentpmx":"dist/agentpmx.js"},"dist":{"shasum":"1c7827e79b1f0323a08cadf59f045d3f76fe1a5e","tarball":"https://registry.npmjs.org/@amajumdar2249/agentpm/-/agentpm-1.1.0.tgz","fileCount":31,"integrity":"sha512-e7U8+puT3gl9mJD6BGiLO1DYSNSNjXB+9lW76GBycdWjNs+tbyCGZ/hWnhPsxWT2uYZqQWKlHd3cIkCW4cjqVQ==","signatures":[{"sig":"MEQCIHcwz5cf2WVvTOa2zmMw66O1JZ20OVPd7DW9YgzE0NV9AiA2MMUUqZc7L81Km1UJZu++sKOn2bPFyRB8TUhzGFbSHA==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":121913},"main":"dist/index.js","engines":{"node":">=18.0.0"},"gitHead":"30a627166d010fbe57b13e4805f82239a0a68499","scripts":{"dev":"ts-node src/index.ts","test":"jest --runInBand","build":"tsc","prepare":"npm run build","prepublishOnly":"npm run build"},"_npmUser":{"name":"amajumdar2249","email":"amajumdar2249@gmail.com"},"repository":{"url":"git+https://github.com/amajumdar2249/agentpm.git","type":"git"},"_npmVersion":"11.11.0","description":"AgentPM: The Definitive Package Manager and Security Auditor for AI Agents. Securely discover, audit, and install AI skills to build the ultimate agentic ecosystem.","directories":{},"_nodeVersion":"24.14.1","dependencies":{"ink":"^3.2.0","ora":"^5.4.1","zod":"^3.22.4","chalk":"^4.1.2","react":"^19.2.7","sigstore":"^4.1.1","commander":"^11.0.0","minisearch":"^7.2.0","ink-text-input":"^4.0.3","@e2b/code-interpreter":"^2.6.1","@modelcontextprotocol/sdk":"^1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^29.7.0","ts-jest":"^29.1.2","ts-node":"^10.9.2","typescript":"^5.9.3","@types/jest":"^29.5.12","@types/react":"^19.2.17"},"_npmOperationalInternal":{"tmp":"tmp/agentpm_1.1.0_1782841784520_0.842102008803997","host":"s3://npm-registry-packages-npm-production"}},"1.2.0":{"name":"@amajumdar2249/agentpm","version":"1.2.0","keywords":["ai-agent","package-manager","skills","prompt-injection","security","mcp","claude-code","cursor","agentpm","cli"],"author":{"name":"amajumdar2249"},"license":"MIT","_id":"@amajumdar2249/agentpm@1.2.0","maintainers":[{"name":"amajumdar2249","email":"amajumdar2249@gmail.com"}],"homepage":"https://github.com/amajumdar2249/agentpm","bugs":{"url":"https://github.com/amajumdar2249/agentpm/issues"},"bin":{"agentpm":"dist/index.js","agentpmx":"dist/agentpmx.js"},"dist":{"shasum":"759749fb6580080ec61629756628382f7666e398","tarball":"https://registry.npmjs.org/@amajumdar2249/agentpm/-/agentpm-1.2.0.tgz","fileCount":32,"integrity":"sha512-i7FuZSH1eiMMlOWURJW9ti8sxu1pCOen8ds4fVulLhQL6BC+SM24x8Jy9PYd/l1X1VkkUmCBiAaGoYWbUtRuCw==","signatures":[{"sig":"MEYCIQCIYrZSssOlzo92xtchuxu99Mf4t1cFnBRyY6jYTLxrzgIhAJf+4hJpqfy79k5ui74XG62Czp8owbLmomAEIn9tuUVe","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":125788},"main":"dist/index.js","engines":{"node":">=18.0.0"},"gitHead":"e3fbc05b883856ce069166ae84ea2d1d790ecb53","scripts":{"dev":"ts-node src/index.ts","test":"jest --runInBand","build":"tsc","prepare":"npm run build","prepublishOnly":"npm run build"},"_npmUser":{"name":"amajumdar2249","email":"amajumdar2249@gmail.com"},"repository":{"url":"git+https://github.com/amajumdar2249/agentpm.git","type":"git"},"_npmVersion":"11.11.0","description":"AgentPM: The Definitive Package Manager and Security Auditor for AI Agents. Securely discover, audit, and install AI skills to build the ultimate agentic ecosystem.","directories":{},"_nodeVersion":"24.14.1","dependencies":{"ink":"^3.2.0","ora":"^5.4.1","zod":"^3.22.4","chalk":"^4.1.2","react":"^19.2.7","sigstore":"^4.1.1","commander":"^11.0.0","minisearch":"^7.2.0","ink-text-input":"^4.0.3","@e2b/code-interpreter":"^2.6.1","@modelcontextprotocol/sdk":"^1.29.0"},"_hasShrinkwrap":false,"devDependencies":{"jest":"^29.7.0","ts-jest":"^29.1.2","ts-node":"^10.9.2","typescript":"^5.9.3","@types/jest":"^29.5.12","@types/react":"^19.2.17"},"_npmOperationalInternal":{"tmp":"tmp/agentpm_1.2.0_1782872231475_0.9250090049956594","host":"s3://npm-registry-packages-npm-production"}},"1.3.0":{"name":"@amajumdar2249/agentpm","version":"1.3.0","description":"The Package Manager for AI Agents. Discover, audit, and install AI skills and prompts.","main":"dist/index.js","bin":{"agentpm":"dist/index.js","agentpmx":"dist/agentpmx.js"},"scripts":{"build":"tsc","test":"node dist/index.js audit","dev":"ts-node src/index.ts","prepublishOnly":"npm run build"},"keywords":["ai","agents","package-manager","prompt-injection","security","claude-code","cursor","windsurf","mcp"],"author":{"name":"Aurgho Majumdar"},"license":"MIT","dependencies":{"@modelcontextprotocol/sdk":"^0.6.0","chalk":"^4.1.2","commander":"^11.1.0","ink":"^4.4.1","ink-text-input":"^5.0.1","minisearch":"^6.3.0","ora":"^5.4.1","react":"^18.2.0","sigstore":"^2.1.0","vm2":"^3.9.19","zod":"^3.22.4"},"devDependencies":{"@types/node":"^20.10.0","@types/ora":"^3.2.0","@types/react":"^18.2.0","typescript":"^5.3.3"},"gitHead":"70fde9cfa3159611ee41bfb4cbc593e73d9d6a84","_id":"@amajumdar2249/agentpm@1.3.0","_nodeVersion":"24.19.0","_npmVersion":"11.17.0","dist":{"integrity":"sha512-zydAp9m+L0V2obfhRSCvAXtGdxNUXbFAaqQ8nO0y1AMqPhkLZrtn2KnO71Vf31wYTUIIvI0lxFkI0A/EZi7+rg==","shasum":"a1b5e92484f33637a29f07fb569b7723db429be9","tarball":"https://registry.npmjs.org/@amajumdar2249/agentpm/-/agentpm-1.3.0.tgz","fileCount":35,"unpackedSize":151036,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIEEEcfqLqqcRRrb1Wnif5CVRKFZu9zMWI/UkKRLlmK2WAiEAta1FXSTnXHpalT2i5W+RyHF/p4c2ryBfmBST+0IRvtk="}]},"_npmUser":{"name":"amajumdar2249","email":"amajumdar2249@gmail.com"},"directories":{},"maintainers":[{"name":"amajumdar2249","email":"amajumdar2249@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/agentpm_1.3.0_1786738524880_0.6061319306088919"},"_hasShrinkwrap":false}},"time":{"created":"2026-06-30T17:49:44.355Z","modified":"2026-08-14T20:15:25.242Z","1.1.0":"2026-06-30T17:49:44.672Z","1.2.0":"2026-07-01T02:17:11.637Z","1.3.0":"2026-08-14T20:15:25.090Z"},"author":{"name":"Aurgho Majumdar"},"license":"MIT","keywords":["ai","agents","package-manager","prompt-injection","security","claude-code","cursor","windsurf","mcp"],"description":"The Package Manager for AI Agents. Discover, audit, and install AI skills and prompts.","maintainers":[{"name":"amajumdar2249","email":"amajumdar2249@gmail.com"}],"readme":"# 📦 agentpm\n\n> **The Package Manager for AI Agents.**  \n> Securely discover, audit, and install AI skills and system prompts.\n\n[![Build Status](https://img.shields.io/github/actions/workflow/status/amajumdar2249/agentpm/ci.yml?branch=main&style=flat-square)](https://github.com/amajumdar2249/agentpm/actions)\n[![License: MIT](https://img.shields.io/badge/License-MIT-blue.svg?style=flat-square)](https://opensource.org/licenses/MIT)\n[![NPM Version](https://img.shields.io/npm/v/@amajumdar2249/agentpm?style=flat-square)](https://www.npmjs.com/package/@amajumdar2249/agentpm)\n[![TypeScript](https://img.shields.io/badge/%3C%2F%3E-TypeScript-%230074c1.svg?style=flat-square)](http://www.typescriptlang.org/)\n\n---\n\n## ❌ The Problem\nAs AI-assisted IDEs (Claude Code, Cursor, Windsurf) take over, developers are manually copy-pasting system prompts, rules, and \"skills\" from random gists, blogs, and repos. There is **no standard way** to manage, version, or secure your AI's custom instructions. Even worse, blindly copying prompts leads to **Prompt Injection Vulnerabilities**.\n\n## ✅ The Solution\n`agentpm` brings the `npm` experience to AI Agents. With a single command, you can install the best open-source AI skills directly into your `.agents/` or `.cursorrules` folders.\n\nEvery skill installed via `agentpm` is **automatically audited** for prompt-injection attacks, hidden payloads, and data exfiltration.\n\n```bash\n# Install a high-quality React optimization skill securely\n$ agentpm install react-best-practices\n\n🚀 Initializing install for skill: react-best-practices\n📡 Fetching skill package from agentpm-registry...\n🔍 Scanning for prompt injections, jailbreaks & data exfiltration...\n✅ Zero-Trust Audit Passed: No malicious prompts found.\n📦 Successfully installed react-best-practices into .agents/skills/react-best-practices.md\n```\n\n---\n\n## 🚀 Installation & Getting Started\n\n### 1. Install Globally via NPM\n```bash\nnpm install -g @amajumdar2249/agentpm\n```\n\n### 2. Available Commands\n\n```bash\n# Initialize a new agentic workspace (creates agentpm.json)\nagentpm init\n\n# Search for skills in the 44.5k+ registry\nagentpm search react\n\n# Securely audit and install a skill\nagentpm install react-best-practices\n\n# List all installed skills in current workspace\nagentpm list\n\n# Run zero-trust security audit across all local skills\nagentpm audit\n```\n\n---\n\n## 🛡️ Zero-Trust Security Engine\n`agentpm` includes a real built-in AST & Heuristic security scanner that checks for:\n- **Prompt Injections:** `ignore previous instructions`, `you are now`, `system: you are`\n- **Data Exfiltration:** Hidden HTTP calls attempting to steal `.env` or credentials\n- **System Overrides:** Destructive system commands (`rm -rf`, `format c:`, `drop table`)\n- **Whitespace Hijacking:** Hidden instructions concealed behind 50+ lines of whitespace\n\n---\n\n## 📄 License\nMIT License © 2026 Aurgho Majumdar\n","readmeFilename":"README.md"}