{"_id":"@camunda8/spm","_rev":"11-f621b0720fb2e83c499b8f191b2c5663","name":"@camunda8/spm","dist-tags":{"latest":"0.9.0"},"versions":{"0.1.0":{"name":"@camunda8/spm","version":"0.1.0","keywords":["ai","skills","claude","copilot","package-manager","cli"],"author":{"name":"Camunda"},"license":"Apache-2.0","_id":"@camunda8/spm@0.1.0","maintainers":[{"name":"vobu","email":"vobu+npmjs@posteo.de"},{"name":"sitapati","email":"josh@magikcraft.io"},{"name":"emilyoram","email":"emily.oram@camunda.com"},{"name":"pcab","email":"pablocabrera1985@gmail.com"}],"homepage":"https://github.com/camunda/spm-cli#readme","bugs":{"url":"https://github.com/camunda/spm-cli/issues"},"bin":{"spm":"bin/spm.js"},"dist":{"shasum":"8f5edfd61d3f61bc2059ba6232311ed958499dd1","tarball":"https://registry.npmjs.org/@camunda8/spm/-/spm-0.1.0.tgz","fileCount":4,"integrity":"sha512-gTut/tE/G2wnsF2S67UjMgDlxtRZqrldk2z+GuRbDUx2P7ZUZB1z/iiHOMtX1GKusHSu5WF0x7APJ+V3zV90lw==","signatures":[{"sig":"MEUCIQDkC/1lRTbLY0f53PnU5iFh7AMZpaoDllTQLi2tu4fpUQIgJkDM2XKrlGV5ykHEzLod1ophwLNe1PJYeczxkhWZlro=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":22398},"engines":{"node":">=18"},"gitHead":"24be41439ee97bc6bd69de964101d23e5349e16d","_npmUser":{"name":"pcab","email":"pablocabrera1985@gmail.com"},"repository":{"url":"git+https://github.com/camunda/spm-cli.git","type":"git"},"_npmVersion":"11.17.0","description":"Skill package manager (spm): declare AI skills in ai.json and materialize them for Claude/Copilot.","directories":{},"_nodeVersion":"24.18.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"optionalDependencies":{"@camunda8/spm-linux-x64":"0.1.0","@camunda8/spm-win32-x64":"0.1.0","@camunda8/spm-darwin-x64":"0.1.0","@camunda8/spm-linux-arm64":"0.1.0","@camunda8/spm-darwin-arm64":"0.1.0"},"_npmOperationalInternal":{"tmp":"tmp/spm_0.1.0_1785408046007_0.7421734936407349","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@camunda8/spm","version":"0.1.1","keywords":["ai","skills","claude","copilot","package-manager","cli"],"author":{"name":"Camunda"},"license":"Apache-2.0","_id":"@camunda8/spm@0.1.1","maintainers":[{"name":"vobu","email":"vobu+npmjs@posteo.de"},{"name":"sitapati","email":"josh@magikcraft.io"},{"name":"emilyoram","email":"emily.oram@camunda.com"},{"name":"pcab","email":"pablocabrera1985@gmail.com"}],"homepage":"https://github.com/camunda/spm-cli#readme","bugs":{"url":"https://github.com/camunda/spm-cli/issues"},"bin":{"spm":"bin/spm.js"},"dist":{"shasum":"fdfe57d31d91fecf7887418404385bbb04578f95","tarball":"https://registry.npmjs.org/@camunda8/spm/-/spm-0.1.1.tgz","fileCount":4,"integrity":"sha512-G5BPmaFG5JzfFfEMHmZNJUPjV8AJ9rg6t6PxmMbqtVeziFA4SeONlcu3XMGbqzUlO6+CDyd2B6PNzhir8J7m5g==","signatures":[{"sig":"MEUCIQCAj48k+VDKKeJa6EQSuHKZYq0h7gaG4HE6JbDCUjFdSwIgGQjt8fR0DpQiagBTeRV6FDAKxfJ1WNYIGOJ5EP651B8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":22544},"engines":{"node":">=18"},"gitHead":"1419e50d6c5bc9331195ab7329a7bb0adc0e3bc1","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:f93e2ce2-be44-438d-aeb0-9d88f4502ca5"}},"repository":{"url":"git+https://github.com/camunda/spm-cli.git","type":"git"},"_npmVersion":"11.12.1","description":"Skill package manager (spm): declare AI skills in ai.json and materialize them for Claude/Copilot.","directories":{},"_nodeVersion":"24.18.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"optionalDependencies":{"@camunda8/spm-linux-x64":"0.1.1","@camunda8/spm-win32-x64":"0.1.1","@camunda8/spm-darwin-x64":"0.1.1","@camunda8/spm-linux-arm64":"0.1.1","@camunda8/spm-darwin-arm64":"0.1.1"},"_npmOperationalInternal":{"tmp":"tmp/spm_0.1.1_1785488193137_0.4713271461113977","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@camunda8/spm","version":"0.2.0","keywords":["ai","skills","claude","copilot","package-manager","cli"],"author":{"name":"Camunda"},"license":"Apache-2.0","_id":"@camunda8/spm@0.2.0","maintainers":[{"name":"vobu","email":"vobu+npmjs@posteo.de"},{"name":"sitapati","email":"josh@magikcraft.io"},{"name":"emilyoram","email":"emily.oram@camunda.com"},{"name":"pcab","email":"pablocabrera1985@gmail.com"}],"homepage":"https://github.com/camunda/spm-cli#readme","bugs":{"url":"https://github.com/camunda/spm-cli/issues"},"bin":{"spm":"bin/spm.js"},"dist":{"shasum":"d635e568b7fda09cdd6c5f0de80c47d4b005fcf1","tarball":"https://registry.npmjs.org/@camunda8/spm/-/spm-0.2.0.tgz","fileCount":4,"integrity":"sha512-X5EmKsqpRQjQdGOdmhBonRi1IquaK77PvewDWRI22Rmw3xk3WiZPGlMcgvjm2Pf+ELIOQ37u9ultnzB6X10N5w==","signatures":[{"sig":"MEUCIBerXOIIfQn/xcoF1ejpmo87vLA+7/Jap4gtcqkl1GIIAiEA23Y/Na5vetSaG+wBUB5HdycXrb0keXYsFNxxtQgHBZ0=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":25094},"engines":{"node":">=18"},"gitHead":"8d8bac02f24717425b6c94ec34ff5a4a99c858d6","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:f93e2ce2-be44-438d-aeb0-9d88f4502ca5"}},"repository":{"url":"git+https://github.com/camunda/spm-cli.git","type":"git"},"_npmVersion":"11.12.1","description":"Skill package manager (spm): declare AI skills in ai.json and materialize them for Claude/Copilot.","directories":{},"_nodeVersion":"24.18.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"optionalDependencies":{"@camunda8/spm-linux-x64":"0.2.0","@camunda8/spm-win32-x64":"0.2.0","@camunda8/spm-darwin-x64":"0.2.0","@camunda8/spm-linux-arm64":"0.2.0","@camunda8/spm-darwin-arm64":"0.2.0"},"_npmOperationalInternal":{"tmp":"tmp/spm_0.2.0_1785792020306_0.46380157261932387","host":"s3://npm-registry-packages-npm-production"}},"0.3.0":{"name":"@camunda8/spm","version":"0.3.0","keywords":["ai","skills","claude","copilot","package-manager","cli"],"author":{"name":"Camunda"},"license":"Apache-2.0","_id":"@camunda8/spm@0.3.0","maintainers":[{"name":"vobu","email":"vobu+npmjs@posteo.de"},{"name":"sitapati","email":"josh@magikcraft.io"},{"name":"emilyoram","email":"emily.oram@camunda.com"},{"name":"pcab","email":"pablocabrera1985@gmail.com"}],"homepage":"https://github.com/camunda/spm-cli#readme","bugs":{"url":"https://github.com/camunda/spm-cli/issues"},"bin":{"spm":"bin/spm.js"},"dist":{"shasum":"123d4aff2d8c9c012f10f010f07bad9202b1176b","tarball":"https://registry.npmjs.org/@camunda8/spm/-/spm-0.3.0.tgz","fileCount":4,"integrity":"sha512-SyXZNE06m6HVcnjCJTKkbMNy25YXpemv4xDWc/l85ySpclOazvT4PdHXewolFOKwJztMBPeE2MgBa1fkNfe8hw==","signatures":[{"sig":"MEQCIHPVwpU5wgVXhesPEuYZMwYfWwZflRhigPKNwSb/NKkbAiBkM3WdW6l6v2XNHT7UAMjA5hrvovxIY8Qpr7cWPrftMQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":25665},"engines":{"node":">=18"},"gitHead":"096b1bbab9d07b0a0b20dbbf112ad7fcb146a414","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:f93e2ce2-be44-438d-aeb0-9d88f4502ca5"}},"repository":{"url":"git+https://github.com/camunda/spm-cli.git","type":"git"},"_npmVersion":"11.12.1","description":"Skill package manager (spm): declare AI skills in ai.json and materialize them for Claude/Copilot.","directories":{},"_nodeVersion":"24.18.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"optionalDependencies":{"@camunda8/spm-linux-x64":"0.3.0","@camunda8/spm-win32-x64":"0.3.0","@camunda8/spm-darwin-x64":"0.3.0","@camunda8/spm-linux-arm64":"0.3.0","@camunda8/spm-darwin-arm64":"0.3.0"},"_npmOperationalInternal":{"tmp":"tmp/spm_0.3.0_1785967156168_0.6899484499178765","host":"s3://npm-registry-packages-npm-production"}},"0.4.0":{"name":"@camunda8/spm","version":"0.4.0","keywords":["ai","skills","claude","copilot","package-manager","cli"],"author":{"name":"Camunda"},"license":"Apache-2.0","_id":"@camunda8/spm@0.4.0","maintainers":[{"name":"vobu","email":"vobu+npmjs@posteo.de"},{"name":"sitapati","email":"josh@magikcraft.io"},{"name":"emilyoram","email":"emily.oram@camunda.com"},{"name":"pcab","email":"pablocabrera1985@gmail.com"}],"homepage":"https://github.com/camunda/spm-cli#readme","bugs":{"url":"https://github.com/camunda/spm-cli/issues"},"bin":{"spm":"bin/spm.js"},"dist":{"shasum":"bbe282116e6c7f54748f3c6f8c83c1dc9836178f","tarball":"https://registry.npmjs.org/@camunda8/spm/-/spm-0.4.0.tgz","fileCount":4,"integrity":"sha512-RC/f0D1T+pNghw30w91k0IpJyQaTbfyHMK/+L2lYmZV7DCKervKMwmP2wIJdHpxlemLZMqvfxt1SIdc62ZhDWg==","signatures":[{"sig":"MEUCIQCsYOo5ZbxD5ZD0nHslGX2ItmQiQ8dvXgLN5pGxU43sZAIgbg3viCKEQmod0Wkk0eJM+lXyX2uGO8VIWjAxNGb2opo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":25768},"engines":{"node":">=18"},"gitHead":"fb4546d25a227349a41492ad9b1f3ddbbe34b4be","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:f93e2ce2-be44-438d-aeb0-9d88f4502ca5"}},"repository":{"url":"git+https://github.com/camunda/spm-cli.git","type":"git"},"_npmVersion":"11.12.1","description":"Skill package manager (spm): declare AI skills in ai.json and materialize them for Claude/Copilot.","directories":{},"_nodeVersion":"24.18.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"optionalDependencies":{"@camunda8/spm-linux-x64":"0.4.0","@camunda8/spm-win32-x64":"0.4.0","@camunda8/spm-darwin-x64":"0.4.0","@camunda8/spm-linux-arm64":"0.4.0","@camunda8/spm-darwin-arm64":"0.4.0"},"_npmOperationalInternal":{"tmp":"tmp/spm_0.4.0_1786020824831_0.030045892884350334","host":"s3://npm-registry-packages-npm-production"}},"0.5.0":{"name":"@camunda8/spm","version":"0.5.0","keywords":["ai","skills","claude","copilot","package-manager","cli"],"author":{"name":"Camunda"},"license":"Apache-2.0","_id":"@camunda8/spm@0.5.0","maintainers":[{"name":"vobu","email":"vobu+npmjs@posteo.de"},{"name":"sitapati","email":"josh@magikcraft.io"},{"name":"emilyoram","email":"emily.oram@camunda.com"},{"name":"pcab","email":"pablocabrera1985@gmail.com"}],"homepage":"https://github.com/camunda/spm-cli#readme","bugs":{"url":"https://github.com/camunda/spm-cli/issues"},"bin":{"spm":"bin/spm.js"},"dist":{"shasum":"ad9feef0f3cfc5f71a26278f81f021a846a8501e","tarball":"https://registry.npmjs.org/@camunda8/spm/-/spm-0.5.0.tgz","fileCount":4,"integrity":"sha512-S+UessP2IEyxU36v1rEuVRijJFvJpEHyjvj0IIuuKTf/pIgbms9gqYaH1yQN+42fmk2E+StH03XviEFDyg4q0Q==","signatures":[{"sig":"MEUCIQD+TkI/QqUSsHxVO+w8ZjMxmatXen9syQe6A754UfHkTQIgK+bWyojSkCd7o4k4guFAHBtj+wRHuab0dhRlJRwRS8s=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":25889},"engines":{"node":">=18"},"gitHead":"2d17e6fc2d99126a87a407ae96e5a26dea8c5800","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:f93e2ce2-be44-438d-aeb0-9d88f4502ca5"}},"repository":{"url":"git+https://github.com/camunda/spm-cli.git","type":"git"},"_npmVersion":"11.12.1","description":"Skill package manager (spm): declare AI skills in ai.json and materialize them for Claude/Copilot.","directories":{},"_nodeVersion":"24.18.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"optionalDependencies":{"@camunda8/spm-linux-x64":"0.5.0","@camunda8/spm-win32-x64":"0.5.0","@camunda8/spm-darwin-x64":"0.5.0","@camunda8/spm-linux-arm64":"0.5.0","@camunda8/spm-darwin-arm64":"0.5.0"},"_npmOperationalInternal":{"tmp":"tmp/spm_0.5.0_1786357067515_0.23851157496611508","host":"s3://npm-registry-packages-npm-production"}},"0.6.0":{"name":"@camunda8/spm","version":"0.6.0","keywords":["ai","skills","claude","copilot","package-manager","cli"],"author":{"name":"Camunda"},"license":"Apache-2.0","_id":"@camunda8/spm@0.6.0","maintainers":[{"name":"vobu","email":"vobu+npmjs@posteo.de"},{"name":"sitapati","email":"josh@magikcraft.io"},{"name":"emilyoram","email":"emily.oram@camunda.com"},{"name":"pcab","email":"pablocabrera1985@gmail.com"}],"homepage":"https://github.com/camunda/spm-cli#readme","bugs":{"url":"https://github.com/camunda/spm-cli/issues"},"bin":{"spm":"bin/spm.js"},"dist":{"shasum":"26a069e4b3938f9e528299326ecd1efec48a285a","tarball":"https://registry.npmjs.org/@camunda8/spm/-/spm-0.6.0.tgz","fileCount":4,"integrity":"sha512-lSF+9T8V8pgYVpWWl342yg2c7wCZJ29/o5UW/VzkYWCExt4YCSxqPg99eHFivkddgB+lzJw1GK79HFI4nd+BAQ==","signatures":[{"sig":"MEYCIQCEOlm24rVD0Ga25I/q2Mi0z2dhgQm/1u26KtkQcdoc8gIhAMYLYoNZjEA/s7MnCnvzqvLW9VUg5CyIfCUV/i1LD1xu","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIQCZgvu17hBI9m3BAha9ZxOGdwO/uj4dxXeNk5GydOX+mgIgSJOvzRAVrfDnmARd8ZwUmpb7r8p046QzdXwsFsWMODA=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@camunda8%2fspm@0.6.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":28497},"engines":{"node":">=18"},"gitHead":"6cb30f4722ec89670247b386f27e6caf5ae23276","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:f93e2ce2-be44-438d-aeb0-9d88f4502ca5"}},"repository":{"url":"git+https://github.com/camunda/spm-cli.git","type":"git"},"_npmVersion":"11.12.1","description":"Skill package manager (spm): declare AI skills in ai.json and materialize them for Claude/Copilot.","directories":{},"_nodeVersion":"24.19.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"optionalDependencies":{"@camunda8/spm-linux-x64":"0.6.0","@camunda8/spm-win32-x64":"0.6.0","@camunda8/spm-darwin-x64":"0.6.0","@camunda8/spm-linux-arm64":"0.6.0","@camunda8/spm-darwin-arm64":"0.6.0"},"_npmOperationalInternal":{"tmp":"tmp/spm_0.6.0_1787350559747_0.10555764915538379","host":"s3://npm-registry-packages-npm-production"}},"0.7.0":{"name":"@camunda8/spm","version":"0.7.0","keywords":["ai","skills","claude","copilot","package-manager","cli"],"author":{"name":"Camunda"},"license":"Apache-2.0","_id":"@camunda8/spm@0.7.0","maintainers":[{"name":"vobu","email":"vobu+npmjs@posteo.de"},{"name":"sitapati","email":"josh@magikcraft.io"},{"name":"emilyoram","email":"emily.oram@camunda.com"},{"name":"pcab","email":"pablocabrera1985@gmail.com"}],"homepage":"https://github.com/camunda/spm-cli#readme","bugs":{"url":"https://github.com/camunda/spm-cli/issues"},"bin":{"spm":"bin/spm.js"},"dist":{"shasum":"4f76e89a9d25876ff3efb580ea27ee16256537d9","tarball":"https://registry.npmjs.org/@camunda8/spm/-/spm-0.7.0.tgz","fileCount":4,"integrity":"sha512-R2/q8r5n5WhgFEAu7VLIBh19d4Q6W7n29XxcuTmZVPwU6bute6a5Ej64X0SyAHjt0ZF4JlB1lk9t4tj50qJl7A==","signatures":[{"sig":"MEQCICgmHjgEOu/Ua1YFHX8x7zBUlbe/aucdLCocLqxkg5DrAiAKNynxmZiRMMDQVVpAIx76cqKLL0LjZrDTlwu2REuK0w==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIAT1JroI23753gJaw2Ghm2PUxAzqFP2IsO3HVJ5/JCBQAiEAsjK4NpsPBdwqhDWA9kGEeLJ6fwFNVzWzJChgkEOuppw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@camunda8%2fspm@0.7.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":32194},"engines":{"node":">=18"},"gitHead":"ea83dc09b4b979481ed0b204247f961b7feedd45","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:f93e2ce2-be44-438d-aeb0-9d88f4502ca5"}},"repository":{"url":"git+https://github.com/camunda/spm-cli.git","type":"git"},"_npmVersion":"11.12.1","description":"Skill package manager (spm): declare AI skills in ai.json and materialize them for Claude/Copilot.","directories":{},"_nodeVersion":"24.19.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"optionalDependencies":{"@camunda8/spm-linux-x64":"0.7.0","@camunda8/spm-win32-x64":"0.7.0","@camunda8/spm-darwin-x64":"0.7.0","@camunda8/spm-linux-arm64":"0.7.0","@camunda8/spm-darwin-arm64":"0.7.0"},"_npmOperationalInternal":{"tmp":"tmp/spm_0.7.0_1787564043944_0.8208714964473134","host":"s3://npm-registry-packages-npm-production"}},"0.8.0":{"name":"@camunda8/spm","version":"0.8.0","keywords":["ai","skills","claude","copilot","package-manager","cli"],"author":{"name":"Camunda"},"license":"Apache-2.0","_id":"@camunda8/spm@0.8.0","maintainers":[{"name":"vobu","email":"vobu+npmjs@posteo.de"},{"name":"sitapati","email":"josh@magikcraft.io"},{"name":"emilyoram","email":"emily.oram@camunda.com"},{"name":"pcab","email":"pablocabrera1985@gmail.com"}],"homepage":"https://github.com/camunda/spm-cli#readme","bugs":{"url":"https://github.com/camunda/spm-cli/issues"},"bin":{"spm":"bin/spm.js"},"dist":{"shasum":"da226c0f583d252db3d3f2d9c2f82ee04a69a314","tarball":"https://registry.npmjs.org/@camunda8/spm/-/spm-0.8.0.tgz","fileCount":4,"integrity":"sha512-oA349SgBWOGFyn9luSHKAwpW9/KAQ1JgJZ0uo7fcT/StimhAXEfp5aRNCiR5c9zYRbDp0C6nNzuPV6o4KDC3qA==","signatures":[{"sig":"MEUCIQC1ydOOQ0nWWFbzrLM9QWq6iZ3YtXPYbVJgWLV9iFohcgIgdfwWOp6xUdTxtDhrhLLEpKCcmNS7SoZkXyAZw2Lr+QU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIQD6FLjeRL0Wy+zkT4vDS4pGyXGpkzPx5y2fAZWwhL0wZQIgEEBFK0yisxP6DTpFTCx+xSVQtoLxQOcUBte81EOIqP4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@camunda8%2fspm@0.8.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":35558},"engines":{"node":">=18"},"gitHead":"3c9aecb89d2e5e0e900971203c44f599852387a4","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:f93e2ce2-be44-438d-aeb0-9d88f4502ca5"}},"repository":{"url":"git+https://github.com/camunda/spm-cli.git","type":"git"},"_npmVersion":"11.12.1","description":"Skill package manager (spm): declare AI skills in ai.json and materialize them for Claude/Copilot.","directories":{},"_nodeVersion":"24.19.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"optionalDependencies":{"@camunda8/spm-linux-x64":"0.8.0","@camunda8/spm-win32-x64":"0.8.0","@camunda8/spm-darwin-x64":"0.8.0","@camunda8/spm-linux-arm64":"0.8.0","@camunda8/spm-darwin-arm64":"0.8.0"},"_npmOperationalInternal":{"tmp":"tmp/spm_0.8.0_1788259355191_0.35612817126983853","host":"s3://npm-registry-packages-npm-production"}},"0.9.0":{"name":"@camunda8/spm","version":"0.9.0","keywords":["ai","skills","claude","copilot","package-manager","cli"],"author":{"name":"Camunda"},"license":"Apache-2.0","_id":"@camunda8/spm@0.9.0","maintainers":[{"name":"vobu","email":"vobu+npmjs@posteo.de"},{"name":"sitapati","email":"josh@magikcraft.io"},{"name":"emilyoram","email":"emily.oram@camunda.com"},{"name":"pcab","email":"pablocabrera1985@gmail.com"}],"homepage":"https://github.com/camunda/spm-cli#readme","bugs":{"url":"https://github.com/camunda/spm-cli/issues"},"bin":{"spm":"bin/spm.js"},"dist":{"shasum":"c68873c97206d8128f13b6d8f0bc436b9d83a501","tarball":"https://registry.npmjs.org/@camunda8/spm/-/spm-0.9.0.tgz","fileCount":4,"integrity":"sha512-pSwXre6+kWtypEBHRrW2J017epNNs7L8Gq06EI8kfX7S7N9TCO6fbWrmDnhNF91ucDXSsjJwBit/XK7cjo9B4g==","signatures":[{"sig":"MEUCIQDYpj7CNslnU26pumVmmb3vaYRkXD68d/iHqZ6S1vd6KgIgTuD7+vHoo/6duW0NnA6+Uh0AEd3uuVpBrgGiPhbbs6w=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEUCIQCYKZcMVvz6PxQdjSPhLlDvo/y1jzx7IcjzThGIaur9zAIgTlqZeALRMNmhKxYORbEVgkKPCDqVwmt6jBqJNWbb/Tw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@camunda8%2fspm@0.9.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":35558},"engines":{"node":">=18"},"gitHead":"b2992c8acfb3f690606d7988cf4de542972341fd","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:f93e2ce2-be44-438d-aeb0-9d88f4502ca5"}},"repository":{"url":"git+https://github.com/camunda/spm-cli.git","type":"git"},"_npmVersion":"11.12.1","description":"Skill package manager (spm): declare AI skills in ai.json and materialize them for Claude/Copilot.","directories":{},"_nodeVersion":"24.20.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"optionalDependencies":{"@camunda8/spm-linux-x64":"0.9.0","@camunda8/spm-win32-x64":"0.9.0","@camunda8/spm-darwin-x64":"0.9.0","@camunda8/spm-linux-arm64":"0.9.0","@camunda8/spm-darwin-arm64":"0.9.0"},"_npmOperationalInternal":{"tmp":"tmp/spm_0.9.0_1789041992604_0.14981252051292682","host":"s3://npm-registry-packages-npm-production"}}},"time":{"created":"2026-07-30T10:40:45.855Z","modified":"2026-09-16T06:30:14.324Z","0.1.0":"2026-07-30T10:40:46.142Z","0.1.1":"2026-07-31T08:56:33.275Z","0.2.0":"2026-08-03T21:20:20.464Z","0.3.0":"2026-08-05T21:59:16.305Z","0.4.0":"2026-08-06T12:53:44.960Z","0.5.0":"2026-08-10T10:17:47.660Z","0.6.0":"2026-08-21T22:15:59.838Z","0.7.0":"2026-08-24T09:34:04.009Z","0.8.0":"2026-09-01T10:42:35.287Z","0.9.0":"2026-09-10T12:06:32.698Z"},"bugs":{"url":"https://github.com/camunda/spm-cli/issues"},"author":{"name":"Camunda"},"license":"Apache-2.0","homepage":"https://github.com/camunda/spm-cli#readme","keywords":["ai","skills","claude","copilot","package-manager","cli"],"repository":{"url":"git+https://github.com/camunda/spm-cli.git","type":"git"},"description":"Skill package manager (spm): declare AI skills in ai.json and materialize them for Claude/Copilot.","maintainers":[{"email":"vobu+npmjs@posteo.de","name":"vobu"},{"email":"josh@magikcraft.io","name":"sitapati"},{"email":"emily.oram@camunda.com","name":"emilyoram"},{"email":"jan.ladleif@camunda.com","name":"camunda-jan"},{"email":"pablocabrera1985@gmail.com","name":"pcab"}],"readme":"# spm — skill package manager\n\nDeclare AI skills as git dependencies in `ai.json`, and `spm` wires them into your\nAI tool (Amp, Claude Code, Cline, OpenAI Codex CLI, GitHub Copilot CLI, Cursor, Gemini CLI and Windsurf) **without ever committing\nskills to your repo**. Anything spm materializes into the working tree is\ngitignored — no symlinks, no skills under version control.\n\n📖 **Documentation:** <https://camunda.github.io/spm-cli/> (built from\n[`docs/`](docs/) and deployed via GitHub Pages).\n\n## How it works\n\n```\nai.json ──resolve──▶ ai.lock ──fetch──▶ ~/.spm/store/<repo>@<sha>   (global cache, one clone per commit)\n                                              │\n                                              └─project──▶ materialized where the vendor expects it (see below)\n```\n\n- **`ai.json`** — you author it, commit it. Declares target vendors + skill deps.\n- **`ai.lock`** — generated, commit it. Pins every version selector to an immutable commit SHA → reproducible installs.\n- **Global store** (`~/.spm/store`) — a **fetch cache only**: each repo@commit is cloned once and shared across all projects. Nothing is *registered* or *materialized* here — it exists purely so repeated installs don't re-clone.\n- **Vendor projection** — spm copies the store's skills into the directory where each vendor loads them from. In the default **project** scope that is a **project-local**, gitignored dir — nothing spm generates is committed. With `-g`/`--global` (see [Global skills](#global-skills--g----global)) it materializes into a **user-global** location shared across all your projects instead.\n- **Registration** differs per vendor:\n  - **Claude** — spm assembles a self-contained plugin marketplace in the **project-local**, gitignored `.spm/claude/` dir and writes a pointer to it into `.claude/settings.local.json` (gitignored by convention). The dir sits outside `.agents/skills/` so Copilot's scanner never picks it up. Declarative, per-project, zero VCS footprint.\n  - **Copilot CLI** — spm copies the resolved skills into a **project-local** directory, `.agents/skills/spm-managed-skills/<name>/`, where Copilot CLI auto-discovers them (`.agents/skills/**/SKILL.md`). That directory is added to the project's `.gitignore` (with an explanatory comment) so the materialized skills stay truly local and are never committed. No user-global state, no `copilot` CLI required.\n  - **Gemini CLI** — spm copies the resolved skills one directory deep into the tool-native `.gemini/skills/<name>/`, where Gemini CLI auto-discovers them. Because Gemini treats that dir as a team-shared, version-controlled location, spm shares it with your own hand-authored skills: it never wipes the dir, touches only the entries it manages, and gitignores just those spm-managed subdirs (`.gemini/skills/<name>/`) so they stay local while your own skills remain committable.\n  - **Codex CLI** — spm copies the resolved skills one directory deep into the cross-tool `.agents/skills/<name>/` alias (the same standard location Copilot and Gemini can read), where Codex CLI auto-discovers them. Same shared-dir handling as Gemini: spm never wipes the dir, touches only its managed entries, and gitignores just those spm-managed subdirs (`.agents/skills/<name>/`).\n  - **Cursor** — spm copies the resolved skills one directory deep into the tool-native `.cursor/skills/<name>/`, where Cursor auto-discovers them. Same shared-dir handling as Gemini: Cursor treats that dir as version-controlled, so spm never wipes it, touches only the entries it manages, and gitignores just those spm-managed subdirs (`.cursor/skills/<name>/`).\n  - **Cline** — spm copies the resolved skills one directory deep into the tool-native `.cline/skills/<name>/`, where Cline auto-discovers them. Same shared-dir handling as Gemini (never wipes the dir, surgical per-skill add/remove, per-skill gitignore).\n  - **Windsurf** — spm copies the resolved skills one directory deep into the tool-native `.windsurf/skills/<name>/`, where Windsurf's Cascade agent auto-discovers them. Same shared-dir handling as Gemini. (Note: Windsurf's *global* skills live under `~/.codeium/windsurf/skills/`, not `~/.windsurf/`.)\n  - **Amp** — spm copies the resolved skills one directory deep into the cross-tool `.agents/skills/<name>/` alias (Amp's documented default, the same dir Codex reads), where Amp auto-discovers them. Same shared-dir handling as Gemini.\n\nOn a fresh clone, teammates run `spm install` — it repopulates their own fetch cache and re-materializes the project-local skills from `ai.lock`. Same model as `node_modules`.\n\n## ai.json\n\n```json\n{\n  \"targets\": [\"claude\", \"copilot\"],\n  \"skills\": {\n    \"pdf-tools\": { \"git\": \"https://github.com/org/skills\", \"tag\": \"v1.2.0\", \"path\": \"skills/pdf\" },\n    \"reviewer\":  { \"git\": \"https://github.com/me/reviewer\", \"branch\": \"main\" },\n    \"pinned\":    { \"git\": \"https://github.com/x/y\",         \"commit\": \"a1b2c3d\" }\n  }\n}\n```\n\n`targets` lists one or more vendors (`amp`, `claude`, `cline`, `codex`, `copilot`, `cursor`, `gemini`, `windsurf`) — skills\nresolve once and project into each independently.\n\n### Schema & validation\n\n`ai.json` is described by a JSON Schema at [`schema/ai.schema.json`](schema/ai.schema.json)\n(draft-07). spm embeds it and validates every `ai.json` on load, reporting all\nviolations at once with their JSON path:\n\n```\nerror: in ai.json: ai.json does not match schema:\n  at /skills/x: {\"git\":\"u\"} is not valid under any of the schemas listed in the 'oneOf' keyword\n```\n\nAdd a `\"$schema\"` reference for editor autocompletion/validation:\n\n```json\n{ \"$schema\": \"./schema/ai.schema.json\", \"targets\": [\"claude\"], \"skills\": {} }\n```\n\nVersion selectors (exactly one per skill):\n\n| field    | meaning                                    | locked to      |\n|----------|--------------------------------------------|----------------|\n| `tag`    | git tag (annotated tags deref to commit)   | resolved SHA   |\n| `branch` | branch tip at install/update time          | resolved SHA   |\n| `commit` | exact commit                               | itself         |\n\n`path` (optional) selects a subdirectory — for monorepos holding many skills.\n\n### Full plugins (`plugins`)\n\nAlongside individual `skills`, `ai.json` can depend on a **full Claude Code\nplugin** — one that bundles agents, MCP servers, hooks and scripts in addition\nto (or instead of) skills. Declare it under a `plugins` map, keyed by local\nname, with the same git/version selectors as a skill; `path` points at the\nplugin root (the directory holding `.claude-plugin/plugin.json`):\n\n```json\n{\n  \"targets\": [\"claude\", \"copilot\"],\n  \"plugins\": {\n    \"design-system\": {\n      \"git\": \"https://github.com/camunda/design-system\",\n      \"branch\": \"main\",\n      \"path\": \"plugins/camunda-design-system\"\n    }\n  }\n}\n```\n\nOn install:\n\n- **Claude** gets the whole plugin registered under a dedicated, project-local\n  `spm-plugins` marketplace (`.spm/claude-plugins/`), so its **agents, MCP\n  servers, hooks and scripts** all load — not just its `SKILL.md`.\n- **Every** target (including skills-only ones like Copilot, Gemini, …) still\n  gets the plugin's **bundled skills**, flattened into that target's normal\n  skills dir — a graceful, skills-only degradation.\n- `ai.lock` pins the plugin's commit and records its bundled skill set.\n\nA bundled skill whose name collides with a standalone `skills` entry (or another\nplugin's skill) is a hard error, never a silent overwrite.\n\nAdd or remove a plugin from the CLI with the `--plugin` flag (point `--path` at\nthe plugin root):\n\n```bash\nspm add https://github.com/camunda/design-system --branch main \\\n        --path plugins/camunda-design-system --plugin --name design-system\nspm remove design-system --plugin\n```\n\nTo pull in **every** skill under a directory at once (each immediate\nsubdirectory that has its own `SKILL.md`), add `--all` instead of naming them\none by one:\n\n```bash\nspm add https://github.com/org/repo --tag v1.0.0 --path skills --all\n```\n\nEach sub-skill becomes its own `ai.json` entry, keyed by its directory name\n(`--all` cannot be combined with `--name`). This is the one-shot equivalent of\nthe per-skill `spm add … --path <sub> --name <sub>` commands spm suggests when\nyou point `--path` at a container of skills.\n\n### Repo URLs (HTTPS & SSH)\n\n`git` accepts any URL the system `git` understands:\n\n```bash\nspm add https://github.com/org/repo --tag v1.0.0            # HTTPS\nspm add git@github.com:org/repo.git --branch main           # SSH (scp-style)\nspm add ssh://git@github.com/org/repo.git --branch main     # SSH (url form)\n```\n\n**Any git host works** — spm shells out to `git` and never detects or\nspecial-cases a provider, so GitHub, GitLab, Bitbucket, and self-hosted servers\nare all supported with no extra config:\n\n```bash\nspm add git@bitbucket.org:org/repo.git --branch main        # Bitbucket\nspm add https://gitlab.com/org/repo.git --tag v1.0.0        # GitLab\nspm add ssh://git@git.internal.example.com:7999/p/repo.git --branch main  # self-hosted\n```\n\nSSH auth goes through your ssh-agent / keys — spm never handles credentials.\nPrivate HTTPS repos use your git credential helper. spm runs git with\n`GIT_TERMINAL_PROMPT=0`, so a missing credential fails with a clear error\ninstead of hanging on a prompt (helpers and ssh-agent still work).\n\n## Installation\n\n`spm` ships as a single self-contained binary (needs the system `git` on `PATH`\nat runtime).\n\n**From npm (recommended)** — the zero-setup path on every platform. It puts `spm`\non your `PATH` with no manual steps:\n\n```bash\nnpm i -g @camunda8/spm\nspm --help\n```\n\n`@camunda8/spm` is a thin launcher that pulls in the matching prebuilt binary for\nyour OS/CPU via an optional dependency (`@camunda8/spm-<os>-<cpu>`), so nothing is\ncompiled or downloaded outside npm. Supported: `darwin-x64`, `darwin-arm64`,\n`linux-x64`, `linux-arm64`, `win32-x64`. Update with `npm i -g @camunda8/spm@latest`.\n\n**From crates.io** — build and install from source via Cargo (needs a Rust\ntoolchain). The crate is `spm-cli`; the installed binary is `spm`:\n\n```bash\ncargo install spm-cli\n```\n\n**Prebuilt binary** — download a release asset directly; no authentication\nrequired (the repo is public). The easiest way is the\n[GitHub CLI](https://cli.github.com/):\n\n```bash\n# pick the asset for your platform (see list below); example: Apple Silicon macOS\ngh release download --repo camunda/spm-cli \\\n  --pattern 'spm-aarch64-apple-darwin' --output spm\nchmod +x spm && sudo mv spm /usr/local/bin/\n```\n\n`--repo camunda/spm-cli` with no tag grabs the latest release; add\n`v0.1.0` as the first positional arg to pin a specific version.\n\nWithout `gh`, download straight from the public release URL with `curl`:\n\n```bash\n# latest release; swap the asset name for your platform\ncurl -fsSL -o spm \\\n  https://github.com/camunda/spm-cli/releases/latest/download/spm-aarch64-apple-darwin\nchmod +x spm && sudo mv spm /usr/local/bin/\n```\n\nAssets: `spm-x86_64-unknown-linux-gnu`, `spm-aarch64-unknown-linux-gnu`,\n`spm-x86_64-apple-darwin`, `spm-aarch64-apple-darwin`,\n`spm-x86_64-pc-windows-msvc.exe`.\n\n**From source:**\n\n```bash\ngit clone https://github.com/camunda/spm-cli && cd spm-cli\nmake install                  # release build → /usr/local/bin/spm\nmake install PREFIX=~/.local  # or a custom prefix\n# or: cargo install --path .\n```\n\n## Commands\n\n```bash\nspm init [--target amp|claude|cline|codex|copilot|cursor|gemini|windsurf ...] [-g]  # scaffold ai.json (repeatable / comma-separated)\nspm add <git> (--tag|--branch|--commit <v>) \\      # add + install a skill\n        [--path <subdir>] [--name <local-name>] [--all] [-g]  # --all: add every skill under --path\n        [--plugin]                                 # --plugin: add a full plugin (see \"Full plugins\")\nspm target add [vendor ...]                        # add target vendor(s); no arg = pick interactively\nspm remove <name> [--plugin] [-g]                  # drop a skill (or a plugin with --plugin)\nspm update [name] [-g]                              # re-resolve branches/tags to latest\nspm install [-g]                                   # rebuild from ai.lock (after clone)\nspm list [-g]                                      # show skills + pinned commits\nspm status [-g]                                    # check skills are materialized in this checkout\nspm clean [-g]                                     # remove generated vendor config\nspm prune [--yes]                                  # wipe the global fetch cache ($SPM_HOME/store, default ~/.spm/store)\nspm scan [path]                                    # scan skill content for suspicious patterns (default: .)\n```\n\n## Content scanning (security gate)\n\nSkills are markdown + scripts that Claude/Copilot auto-discover and act on, so a\nmalicious or compromised skill repo could smuggle in a payload that hijacks the\nagent or exfiltrates secrets. spm runs a **deterministic content scan** over every\nfetched skill/plugin *before* it is materialized into an agent-discovered\ndirectory. It flags:\n\n- **Prompt injection** — \"ignore previous instructions\", \"disregard your system prompt\", etc.\n- **Secret/credential exfiltration** — references to `~/.ssh/id_rsa`, `.aws/credentials`, `.git-credentials`, `GITHUB_TOKEN`, … (escalated when paired with an outbound command).\n- **Obfuscation** — zero-width/bidi Unicode control characters, base64/hex blobs that decode to shell commands, and files padded past the 8 MiB scan cap (which would otherwise hide content behind a truncated read).\n- **Command execution / network exfil** — `curl | bash`, `/dev/tcp/…` and `nc -e` reverse shells.\n- **Path traversal** — `../../` requested in skill text.\n- **Auto-run triggers** — `postinstall` scripts, git hooks, bundled `Makefile`s.\n\n**High/critical findings block** `add`/`install`/`update`. To review a source (or\ngate it in CI) run it standalone — it exits non-zero on any blocking finding:\n\n```bash\nspm scan               # scan the current directory\nspm scan ./my-skill    # scan a specific path\n```\n\nTo override the gate for content you trust (or a false positive), set\n`SPM_ALLOW_SUSPICIOUS=1` — findings are then printed as warnings but never block.\n\n## Global skills (`-g` / `--global`)\n\nBy default every command operates on the **project** in the current directory.\nPass `-g` (`--global`) to instead manage a **user-global** set of skills that is\navailable to your AI tools in *every* project:\n\n```bash\nspm init -g --target copilot                       # create the global manifest ($SPM_HOME/ai.json)\nspm add  -g <git> --tag v1.0.0 --name reviewer     # install a skill globally\nspm list -g                                        # list global skills\nspm remove -g reviewer                             # drop a global skill\nspm clean  -g                                      # remove global vendor config\n```\n\n- The global **manifest + lock** live under `$SPM_HOME` (default `~/.spm/ai.json`\n  and `~/.spm/ai.lock`) — commit/sync them with your dotfiles for a reproducible\n  personal setup. They reuse the same fetch cache as project installs.\n- **Where global skills materialize:**\n  - **Copilot CLI** → `~/.copilot/skills/<name>/` (its personal-skills dir). This\n    directory is *shared* with skills you author by hand, so spm only ever\n    touches the entries it manages and never wipes the whole directory.\n  - **Gemini CLI** → `~/.gemini/skills/<name>/` (its user-skills dir). Also\n    *shared* with your own hand-authored skills, so spm touches only its managed\n    entries and never wipes the directory.\n  - **Codex CLI** → `~/.agents/skills/<name>/` (the cross-tool user alias). Also\n    *shared*, so spm touches only its managed entries and never wipes the\n    directory.\n  - **Cursor** → `~/.cursor/skills/<name>/` (its user-skills dir). Also *shared*,\n    so spm touches only its managed entries and never wipes the directory.\n  - **Cline** → `~/.cline/skills/<name>/` (its user-skills dir). Also *shared*, so\n    spm touches only its managed entries and never wipes the directory.\n  - **Windsurf** → `~/.codeium/windsurf/skills/<name>/` (its user-skills dir —\n    note the `~/.codeium/windsurf` path, not `~/.windsurf`). Also *shared*, so spm\n    touches only its managed entries and never wipes the directory.\n  - **Amp** → `~/.config/agents/skills/<name>/` (its user-skills dir). Also\n    *shared*, so spm touches only its managed entries and never wipes the\n    directory.\n  - **Claude** → a self-contained marketplace under `$SPM_HOME/claude-global/`,\n    registered in `~/.claude/settings.json` under the marketplace name\n    `spm-global` (skills invoked as `/spm-global:<name>`). A distinct name keeps\n    it from colliding with a project's `spm` marketplace.\n- A skill installed in **both** scopes collides by name at discovery time\n  (`/spm:foo` vs `/spm-global:foo` for Claude; a duplicate `foo` dir for\n  Copilot). `spm status` warns when it detects such a global/project shadow.\n\n## Worktrees & fresh clones\n\nspm materializes skills into **gitignored** project-local dirs (`.spm/claude/`,\n`.agents/skills/spm-managed-skills/`). Git **worktrees** have their own working\ntree and don't share those untracked files, so — exactly like `node_modules` —\n**each checkout needs its own `spm install`**:\n\n```bash\ngit worktree add ../feature -b feature\ncd ../feature && spm install         # materialize this worktree's skills\n```\n\nSkipping this is the usual reason an agent doesn't see a declared skill in a new\nworktree or a fresh clone. `spm status` tells you at a glance and **exits\nnon-zero** when anything is missing, so it works in scripts too:\n\n```bash\nspm status\n# [claude]  0/1 installed  .../.spm/claude/plugin/skills\n#   reviewer  MISSING\n# error: some declared skills are not materialized in this checkout — run `spm install` here\n```\n\nTo install automatically on every branch checkout and new worktree, add a\n`post-checkout` git hook (worktrees share the repo's `.git/hooks`):\n\n```sh\n# .git/hooks/post-checkout   — then: chmod +x .git/hooks/post-checkout\n#!/bin/sh\n# Re-materialize spm skills so Claude/Copilot always see the declared set.\n[ -f ai.lock ] && command -v spm >/dev/null 2>&1 && spm install >/dev/null 2>&1\nexit 0\n```\n\n> **Claude note:** `spm install` writes the *absolute* path of the current\n> checkout's `.spm/claude/` into that checkout's `.claude/settings.local.json`.\n> Since that file is gitignored, a new worktree either has no registration at all\n> or — if it was copied over — one still pointing at the checkout it came from.\n> Either way, run `spm install` inside the worktree and start (or\n> `/reload-plugins` in) the Claude session from that same worktree; discovery is\n> snapshotted at session start. `spm status` reports a stale pointer explicitly:\n>\n> ```\n>   ! .claude/settings.local.json marketplace points at /repo/.spm/claude, not this checkout (/repo-feature/.spm/claude)\n> ```\n\nTo see what each harness actually loaded: `claude plugin list` /\n`claude plugin marketplace list` for Claude; `copilot skill list` for Copilot.\n\n## Design notes\n\n- **Cross-OS**: shells out to the system `git` (no libgit2 build deps); no symlinks; all paths via `std::path`. Runs on Linux, macOS, Windows.\n- **`SPM_HOME`** overrides the store root (default `~/.spm`, holding only the fetch cache) — used by tests. Vendor output is always project-local and is not affected by `SPM_HOME`.\n- **Vendor adapters**: adding a target means implementing one `Vendor` trait (`src/vendor/`). `claude` assembles a plugin-marketplace layout (`marketplace.json` → `plugin.json` → `skills/<name>/SKILL.md`) into the gitignored project-local `.spm/claude/` and points to it; `copilot` copies skills into the gitignored project-local `.agents/skills/spm-managed-skills/`; the remaining targets (`gemini`, `codex`, `cursor`, `cline`, `windsurf`, `amp`) copy skills one level deep into a shared, team-committable skills dir via the generic `src/vendor/shareddir.rs` adapter — each is just a config row naming its project/global dirs (which may differ, e.g. Windsurf's `~/.codeium/windsurf/skills` and Amp's `~/.config/agents/skills`). All share the `src/vendor/dirskills.rs` copy/remove helpers and keep their materialized files out of VCS via the shared `src/gitignore.rs` helper.\n\n## Development\n\n`make check` runs the full CI gate locally (`fmt-check` + `clippy` + `test`).\n\nTo cut a release, bump the crate version (the single source of truth for\ncrates.io, npm, and the GitHub Release) with `make bump` — `PART=patch|minor|major`\n(default `patch`) or `VERSION=X.Y.Z`. Since `main` is protected, `make bump-pr`\ndoes the bump on a branch and opens the PR for you. See [`RELEASE.md`](RELEASE.md)\nfor the full procedure.\n\nA **pre-commit hook** (fmt + clippy) installs itself automatically via\n[`cargo-husky`](https://github.com/rhysd/cargo-husky) — just run `cargo test`\n(or `cargo build`) once after cloning and the hook lands in `.git/hooks`. The\nhook source lives in [`.cargo-husky/hooks/`](.cargo-husky/hooks). Bypass a\nsingle commit with `git commit --no-verify`.\n\n","readmeFilename":"README.md"}