Copilot Plugin Manager (cpm)
Copilot Plugin Manager or just cpm is a package manager for GitHub Copilot assets. It helps you define, install, update, inspect, and reset plugins, skills, agents, MCPs, hooks, workflows, and instructions with a reproducible manifest and lockfile workflow.
The package is published as
copilot-plugin-manager, but the command you run iscpm.
Why use cpm?
- keep your Copilot setup in
cpm.toml - lock resolved revisions in
cpm.lock - install assets into repository-local or global Copilot locations
- manage assets from marketplace specs, GitHub sources, and local paths
- inspect drift with
overview,show,tree,doctor, andstatus
Install
For one-off usage:
uvx --from copilot-plugin-manager cpm --help
or:
uvx copilot-plugin-manager --help
For a persistent install:
uv tool install copilot-plugin-manager
Or with pip:
pip install copilot-plugin-manager
Quick start
If you installed cpm, use cpm .... If you prefer not to install it globally, replace cpm with uvx --from copilot-plugin-manager cpm in the examples below.
Initialize a new project:
cpm init
Add a plugin and a skill:
cpm add spark@copilot-plugins --plugin
cpm add https://github.com/anthropics/skills/tree/main/skills/pdf --skill
Apply the lockfile to disk:
cpm sync
Inspect what is installed:
cpm list
cpm status
Common examples
Install a plugin from a Copilot marketplace registry:
cpm add spark@copilot-plugins --plugin
Registry plugins delegated to copilot plugin install are effectively global installs. Native plugin bundles added from GitHub tree URLs or local paths still honor local vs global scope.
Install a plugin bundle from a GitHub tree URL:
cpm add https://github.com/github/awesome-copilot/tree/main/plugins/testing-automation --plugin
Install a skill from GitHub:
cpm add https://github.com/anthropics/skills/tree/main/skills/pdf --skill
Inspect one asset in detail:
cpm show testing-automation --plugin
See the consolidated view of manifest, lockfile, and installed state:
cpm overview
Core commands
| Command | What it does |
|---|---|
cpm init |
Create a new cpm.toml and cpm.lock |
cpm add |
Add an asset to the manifest and resolve it |
cpm sync |
Install everything recorded in cpm.lock |
cpm update |
Update one or all managed assets |
cpm remove |
Remove a managed asset |
cpm lock |
Resolve without installing |
cpm reset |
Remove managed state and/or installed assets |
cpm overview |
Show the combined manifest, lockfile, and disk view |
cpm list |
List installed assets |
cpm show |
Show full details for a single asset |
cpm tree |
Show the dependency tree |
cpm doctor |
Verify installed files match the lockfile |
cpm status |
Show drift between manifest, lockfile, and disk |
How cpm works
cpm.tomlrecords the assets you wantcpm.lockrecords the resolved versions and hashescpm syncmaterializes those assets into.github/for local scope or~/.copilot/for global scope- concrete GitHub file and tree sources are fetched directly by
cpm - delegated Copilot plugin installs are used where the Copilot CLI is the installer of record
Documentation
docs/USAGE.mdfor usage detailsCONTRIBUTING.mdfor development and contributor workflowsARCHITECTURE.mdfor the current system design
License
See LICENSE-MIT and LICENSE-APACHE.
Metadata
Release files for copilot-plugin-manager 0.2.2
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| copilot_plugin_manager-0.2.2.tar.gz | 204.4 kB | Details |
Built distributions (wheels)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| copilot_plugin_manager-0.2.2-py3-none-win_amd64.whl | Python 3 | none | Windows x86-64 | Details |
| copilot_plugin_manager-0.2.2-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl | Python 3 | none | Linux glibc 2.17+ x86-64 | Details |
| copilot_plugin_manager-0.2.2-py3-none-macosx_11_0_arm64.whl | Python 3 | none | macOS 11.0+ ARM64 | Details |
Total release size: 24.7 MB
Release files / copilot_plugin_manager-0.2.2.tar.gz
| Download URL | copilot_plugin_manager-0.2.2.tar.gz |
|---|---|
| Size | 204.4 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
00fe95076d7e0326f2f942b285128a54b814dcff2b838fae78ec8d6cf6fb73eb
|
|
BLAKE2b-256 checksum How to use checksums |
1ded3a91e37a7f1eaee84631f4526216c027fec3f916114fbac84d30268e9d52
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Mar 31, 2026.
Transparency logRelease files / copilot_plugin_manager-0.2.2-py3-none-win_amd64.whl
| Download URL | copilot_plugin_manager-0.2.2-py3-none-win_amd64.whl |
|---|---|
| Size | 8.2 MB |
| Tags | Python 3 Windows x86-64 |
|
SHA-256 checksum How to use checksums |
59fdc4eedab5b2d53f6b030832ebe279e3a21a2f709f848b38ec5f028a00ec69
|
|
BLAKE2b-256 checksum How to use checksums |
5dd71f7b282590e8dc473d924015fa461c9aa1cc87d0c804e3f0b054e3dc3c6b
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Mar 31, 2026.
Transparency logRelease files / copilot_plugin_manager-0.2.2-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
| Download URL | copilot_plugin_manager-0.2.2-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl |
|---|---|
| Size | 8.4 MB |
| Tags | Linux glibc 2.17+ x86-64 Python 3 |
|
SHA-256 checksum How to use checksums |
7df5888e1c4854dcd755e47cc8562961a83eb0f9342dc21edad50ea14a08a66f
|
|
BLAKE2b-256 checksum How to use checksums |
661a0fc2d8df11bdc34df59485c14ca065287497fef5807017b277123cbb354a
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Mar 31, 2026.
Transparency logRelease files / copilot_plugin_manager-0.2.2-py3-none-macosx_11_0_arm64.whl
| Download URL | copilot_plugin_manager-0.2.2-py3-none-macosx_11_0_arm64.whl |
|---|---|
| Size | 7.8 MB |
| Tags | Python 3 macOS 11.0+ ARM64 |
|
SHA-256 checksum How to use checksums |
c754edd78ea172742a0500288b902122dfb8ee4ca6961afd322c6d7fb956cb9e
|
|
BLAKE2b-256 checksum How to use checksums |
1938f79e8f73d9a0e18f624b1a0be5c78f2866ece59eafd0f34f5f258467ed7f
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/6.1.0 CPython/3.13.7
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Mar 31, 2026.
Transparency log