Skip to main content

npm for your coding agent. Install packs of skills, subagents, and hooks into any repo, for every major agent.

Project description

agentbundle

PyPI Python License

The installer for agent-ready-repo. Think npm, but for the skills, subagents, and hooks your coding agent runs on. One pack, one command, every major agent — Claude Code, Codex, Cursor, Copilot, Gemini, and Kiro (both the CLI and the IDE).

Quick start

pip install agentbundle

Install into a repo — so everyone who clones it gets the pack. core is the flagship pack, the loop itself:

agentbundle install --pack core

No catalogue argument needed: it defaults to the agent-ready-repo catalogue. It lands in the repo's agent config — subagents and skills included — and you commit it like any other project file. This is the default scope: the pack belongs to the project and the whole team.

Install for yourself, everywhere — so a pack follows you across every project, with no per-repo setup:

agentbundle install --pack desk-research --scope user

User-scope packs land in your home directory, not the repo — they're yours, not the team's, and they're there in every project you open.

The install auto-detects your agent (--adapter overrides). Multi-IDE? Install the same pack for each agent at the same scope — they coexist, and the agents that read .agents/skills/ (codex, cursor, gemini, copilot) share one skill copy instead of fighting over it. To install from a different catalogue, pass it as a trailing argument — a git URL or a local path (agentbundle install --pack core <catalogue>); a config set source <catalogue> makes that the default, and an editable clone (pip install -e) defaults to itself.

More commands

# See what the catalogue offers (bare uses the default; or name one explicitly)
agentbundle list-packs
agentbundle list-profiles

# See what a single pack contains — skills and agents, derived live from its tree
agentbundle show core
agentbundle show core --format json          # stable object for scripts/agents

# See what YOU have installed — pack, adapter, scope, version, and whether
# an upgrade is available (both scopes by default)
agentbundle list-installed
agentbundle list-installed --no-check       # skip the catalogue check (offline, fast)
agentbundle list-installed --check-drift    # also count locally edited files
agentbundle list-installed --format json    # machine-readable JSON (schema_version 1)
agentbundle list-installed --updates-only   # show only rows needing attention

# Install a whole curated profile — a single-scope set of packs — in one command
agentbundle install --profile inception

# Preview any install without writing a file
agentbundle install --pack core --dry-run

# Upgrade to the version the catalogue ships — shows installed → target, asks first
agentbundle upgrade --pack core
agentbundle upgrade --pack core --yes  # skip the prompt (CI)

# Uninstall — previews remove (Tier-1) vs keep (your edits), asks first
agentbundle uninstall --pack core --dry-run
agentbundle uninstall --pack core --yes

list-installed reads your state files (not the catalogue) and reports every installed (pack, adapter) at each scope with its version and a four-value status — up-to-date, upgrade-available, ahead (installed version is newer than catalogue), or unknown; it degrades to unknown (never an error) when the catalogue can't be resolved, and --no-check skips the check entirely. --format json emits a stable JSON contract (schema_version: 1) to stdout — useful for CI automation of upgrade decisions. --updates-only hides up-to-date rows.

show <pack> answers "what skills and agents does this pack contain?" by walking the pack's source tree live on each call — so the answer can't drift, and nothing is persisted. --format json emits a stable object (name, version, description, skills, agents, source) for scripts and agents. When the catalogue can't be resolved, an installed pack still reports its inventory from your state files (marked source: installed-state); a not-installed pack errors.

A profile is a catalogue-curated, single-scope set of packs you install in one command — it declares its own scope, so --scope doesn't apply. Upgrade takes no version — the target is whatever the catalogue you point at declares; to pin a past version, point the catalogue at that git ref. Install a pack that's already there and agentbundle offers to upgrade it instead (--yes runs it straight away).

Mutating commands ask first. uninstall, the --force cleanup, and the upgrade offer all preview what they'll do and confirm before touching anything; --dry-run previews without writing, and --yes skips the prompt for non-interactive / CI use (where, without it, they refuse rather than hang).

Enterprise distribution

For organizations running an internal Artifactory mirror or any static HTTPS server, agentbundle's enterprise distribution capabilities handle the full adoption loop — from org-wide channel configuration to CI-driven bulk upgrades.

Install from an internal Artifactory channel:

# Point agentbundle at your org's channel descriptor (one-time per machine,
# or pre-configured in your org fork — see Org bootstrap below)
agentbundle config set source catalogue+https://artifactory.example.test/agentbundle/catalogues/core/channels/stable.json

agentbundle install --pack core

The channel descriptor points to an immutable versioned archive; agentbundle fetches, verifies its SHA-256 digest, and installs. Pass a bearer token via AGENTBUNDLE_HTTP_BEARER_TOKEN — it is never stored in state, never printed, and never forwarded to a different host.

JSON output for CI pipelines:

# See what's installed and what needs upgrading — machine-readable
agentbundle list-installed --format json
agentbundle list-installed --format json --updates-only

Returns a stable JSON contract (schema_version 1) with per-row status (up-to-date / upgrade-available / ahead / unknown) and machine-readable reason codes for unknown rows. Pipe into jq or your CI annotation step.

Bulk upgrade in one scoped command:

# Upgrade all installed packs in a scope — preflights before any write
agentbundle upgrade --all --scope repo --yes
agentbundle upgrade --all --scope user --format json --yes

Preflights all rows before writing anything; a blocked row stops the run before the filesystem is touched. Partial failure is reported honestly — not described as a rollback. Never silently downgrades an ahead row.

Package your catalogue for Artifactory:

agentbundle package-catalogue \
  --root /path/to/catalogue \
  --bundle my-packs \
  --release 1.0.0 \
  --channel stable \
  --output dist/

Produces a deterministic, reproducible gzip archive (versioned) and a mutable channel descriptor JSON (stable.json), ready to upload to Artifactory. Identical inputs produce byte-identical archives (honors SOURCE_DATE_EPOCH).

Org bootstrap — ship the default channel in your fork:

Add an [organization.artifactory] block to agentbundle/_data/install-defaults.toml in your org's agentbundle fork:

[organization.artifactory]
enabled = true
base-url = "https://artifactory.example.test"
repository = "agentbundle"
bundle = "core"
channel = "stable"

Developers installing from your fork get the internal channel without a manual config set source step. The block ships enabled = false in the public package. A malformed enabled = true config fails closed — no silent fallback to the public source.

See the full enterprise adoption guide at docs/guides/_shared/how-to/use-an-artifactory-catalogue.md for all six flows (org bootstrap, repo-scope CI upgrade, user-scope MDM, source-conflict remediation, disconnected hosts, and security controls).

Build your own catalogue

agentbundle isn't tied to the agent-ready-repo catalogue. Any repo that lays its packs out the same way can use it. A pack is a directory:

my-pack/
  pack.toml                  # name, version, adapter-contract, install scope,
                             # plus rich metadata (license, maintainers, links,
                             # categories, keywords) and a README pointer
  .claude-plugin/
    plugin.json              # Claude Code plugin manifest (hand-authored)
  README.md                  # the pack's portable doc — projected with the pack
  .apm/                      # primitives — projected by the build pipeline
    skills/<name>/
      SKILL.md               # the skill body; one folder per skill
      references/            # progressive-disclosure docs, loaded on demand
      assets/                # templates the skill copies into the repo
    agents/<name>.md         # subagents
    hooks/<name>.py          # lifecycle hooks
  seeds/                     # files scaffolded into the adopter repo

pack.toml is the single source of truth for a pack's metadata. Declare license, [[pack.maintainers]], [pack.links], categories, and keywords once; the build projects the cleanly-mappable subset — plus the pack's README.md — into each distribution route's manifest (the plugin.json / marketplace.json entry), so the catalogue describes each pack richly rather than with a single sentence. Extra fields stay in pack.toml; the projection is deliberately lossy per tool.

Point a catalogue URI (a git URL or a local path) at the repo that holds your packs. Then validate a pack against the adapter contract, render it to preview the projection, and install it into a target repo. scaffold drops a pack's seeds into a fresh directory to start from. The build pipeline (agentbundle.build) is the same engine make build runs.

Org adapter default: If your org ships a private agentbundle wheel (or a fork pinned to your internal catalogue), you can set a default adapter for all developers without requiring them to run agentbundle config set or pass --adapter on every install. Add an [organization] table to _data/install-defaults.toml in your fork:

[organization]
preferred_adapter = "cursor"

The org hint fires after the user-config but before the on-disk IDE probe — so --adapter, user-config, and upgrade state-hints all take priority. An invalid value exits 1 before writing anything. See the agentbundle reference for the full cascade.

Lint your catalogue — shallow structural checks run without extra dependencies:

agentbundle catalogue lint --root .

For full agentskills.io spec compliance (frontmatter key set, description policy, encoding, evals schema), install the lint extra and run with --deep:

pip install 'agentbundle[lint]'
agentbundle catalogue lint --root . --deep

Run Tier-A activation evals to measure whether each covered skill fires on the prompts it should:

agentbundle pack evals run --pack <pack-name> --catalogue-root .

See the pack layout reference and authoring a skill.

Credentials

agentbundle doesn't resolve secrets. Credentialed skills use credbroker, a standalone resolver that keeps cleartext out of the model's reach.

Learn more

The full story — the loop, the reviewers, the pack catalogue — is in the agent-ready-repo README.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

agentbundle-0.17.0.tar.gz (477.4 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

agentbundle-0.17.0-py3-none-any.whl (570.5 kB view details)

Uploaded Python 3

File details

Details for the file agentbundle-0.17.0.tar.gz.

File metadata

  • Download URL: agentbundle-0.17.0.tar.gz
  • Upload date:
  • Size: 477.4 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.14

File hashes

Hashes for agentbundle-0.17.0.tar.gz
Algorithm Hash digest
SHA256 66c610596766524ebccc343823b9643108428ba0f22c1c878c4d7e84f94fe525
MD5 dec8869675baa66d56b5815c1271af6d
BLAKE2b-256 e4a5da947196f7f81539bfde8181fcebddec2bac44bd4a32b2db7d2e82306c4c

See more details on using hashes here.

Provenance

The following attestation bundles were made for agentbundle-0.17.0.tar.gz:

Publisher: release-agentbundle.yml on eugenelim/agent-ready-repo

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file agentbundle-0.17.0-py3-none-any.whl.

File metadata

  • Download URL: agentbundle-0.17.0-py3-none-any.whl
  • Upload date:
  • Size: 570.5 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.14

File hashes

Hashes for agentbundle-0.17.0-py3-none-any.whl
Algorithm Hash digest
SHA256 41934a4842dc1dd9ef447499efaa2cd32d3960f6af2114fd7407cabcbdc23d0e
MD5 6db0c01445d5d475578ffaa87c356734
BLAKE2b-256 5477f8251fa5262b36996ccb397f2c31450f470c0f201a37112d7537729b34ed

See more details on using hashes here.

Provenance

The following attestation bundles were made for agentbundle-0.17.0-py3-none-any.whl:

Publisher: release-agentbundle.yml on eugenelim/agent-ready-repo

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page