abom
abom is a Python CLI for managing agent materials (skills, prompts, MCP configs) as git-backed tools. The recipe list lives in the repo as src/abom/recipes.json. abom install <name> looks up that name and clones the git URL stored there.
Package management
Homepage: https://yanchao1999.github.io/abom/
pip install abom
abom recipes
TestPyPI:
pip install --index-url https://test.pypi.org/simple/ --extra-index-url https://pypi.org/simple/ abom
For local development:
uv sync --extra dev
uv run abom recipes
uv run ruff format --check .
uv run ruff check .
uv run pytest
Version 0.0.2. GitHub Actions runs format, lint, and test on every pull request. A pull request that adds or edits src/abom/recipes.json also runs the recipe pull-check. Pushing a v* tag publishes a GitHub release, TestPyPI, and PyPI from the same build. Pushes to main publish the GitHub Pages site.
Trusted publishing uses the GitHub environments testpypi and pypi. On each index, add this repository as a trusted publisher: workflow deploy.yml, and the matching environment name. The PyPI project name is abom.
Recipes
Add a material by appending an object to the recipes list in src/abom/recipes.json. Name it <publisher>-<material> so the source is visible in the name, then install by that name:
abom install anthropics-skill-creator
kind is skill, prompt, mcp, or package. source.git is the clone URL. source.ref is a branch or tag (main when omitted). source.path is optional; when set, abom link points at that file or directory inside the checkout.
{
"name": "anthropics-example-name",
"kind": "skill",
"description": "One line describing what this material does and when to use it.",
"homepage": "https://example.com/example-name",
"license": "Apache-2.0",
"source": {
"git": "https://github.com/org/repo.git",
"ref": "main",
"path": "path/inside/repo"
}
}
The catalog ships one of each kind:
| Name | Kind | Source |
|---|---|---|
abom-package |
package | YanChao1999/abom repository root |
abom-skill |
skill | YanChao1999/abom skills/abom |
abom-mcp |
mcp | YanChao1999/abom mcp |
anthropics-skill-creator |
skill | anthropics/skills skills/skill-creator |
f-prompts |
prompt | f/prompts.chat PROMPTS.md |
modelcontextprotocol-filesystem |
mcp | modelcontextprotocol/servers src/filesystem |
f-prompts-chat |
package | f/prompts.chat packages/prompts.chat |
abom recipes
abom info anthropics-skill-creator
abom check anthropics-skill-creator
abom install anthropics-skill-creator
abom show anthropics-skill-creator
abom link anthropics-skill-creator /path/to/project
abom check clones the recipe when it is not installed yet, then deletes that temporary checkout. Install runs the same check and keeps the checkout only when it passes. The check confirms the kind and blocks install-time hijacks:
- a skill must be a directory with
SKILL.mdfrontmatter (nameanddescription) - a prompt must be a text prompt file, or a directory of them
- a package must have
package.jsonorpyproject.toml - the checkout must contain a license file, and the recognized license must satisfy the recipe's
licensefield - an mcp must have a server manifest or entry file (
package.json,pyproject.toml,index.ts,index.js,server.py, ormain.py) - clone URLs cannot use a scheme that runs a helper, such as
ext:: - git hooks and filesystem monitors from the cloned repo are not executed
- a symlink that points outside the checkout is rejected
- a prompt, skill, or package lifecycle script that pipes a download into a shell is rejected
Commands
abom install <name>: install the named recipe fromrecipes.jsoninto$ABOM_HOME/tools.abom install <name> <git_url>: clone a git repository that is not in the catalog.abom recipes [query]: list recipes, optionally filtered by name, kind, or description.abom info <name>: print one catalog entry.abom show <name>: print the catalog entry, whether it is installed, and the check result when it is installed.abom check <name>: verify the kind and install safety. Exits with an error when the check fails.abom search [query]: list installed tools, optionally filtered by name.abom remove <name>: remove an installed tool and its receipt.abom link <name> <target_repo> [--link-name <name>]: create a symlink at<target_repo>/.abom/<name>pointing to the installed material.target_repomust already exist.
Set ABOM_HOME to override ~/.abom.
Metadata
Release files for abom 0.0.2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| abom-0.0.2.tar.gz | 20.4 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| abom-0.0.2-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 35.3 kB
Release files / abom-0.0.2.tar.gz
| Download URL | abom-0.0.2.tar.gz |
|---|---|
| Size | 20.4 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
97ca1fba125a52fef4aa9670d750508211889b75e4e5fb3613847a131210c4b6
|
|
BLAKE2b-256 checksum How to use checksums |
63c9f00b59e8e2d4b9ed6e0c81a266a562835c91ef2daa8366551fb63126f8eb
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 7, 2026.
Transparency logRelease files / abom-0.0.2-py3-none-any.whl
| Download URL | abom-0.0.2-py3-none-any.whl |
|---|---|
| Size | 14.9 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
c0da24554eb390cf455dc2b78ae3b701706a12855c50f2f3da1a7848cce188da
|
|
BLAKE2b-256 checksum How to use checksums |
a540b3c9ef2e1409ffc34c3463bb48d47fe42fa4b50f80246a9047f8200d11d0
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Oct 7, 2026.
Transparency log