Skip to main content

Copilot Plugin Manager (cpm)

CI PyPI version

Copilot Plugin Manager or just cpm is a package manager for GitHub Copilot assets. It helps you define, install, update, inspect, and reset plugins, skills, agents, MCPs, hooks, workflows, and instructions with a reproducible manifest and lockfile workflow.

The package is published as copilot-plugin-manager, but the command you run is cpm.

Why use cpm?

  • keep your Copilot setup in cpm.toml
  • lock resolved revisions in cpm.lock
  • install assets into repository-local or global Copilot locations
  • manage assets from marketplace specs, GitHub sources, and local paths
  • inspect drift with overview, show, tree, doctor, and status

Install

For one-off usage:

uvx --from copilot-plugin-manager cpm --help

or:

uvx copilot-plugin-manager --help

For a persistent install:

uv tool install copilot-plugin-manager

Or with pip:

pip install copilot-plugin-manager

Quick start

If you installed cpm, use cpm .... If you prefer not to install it globally, replace cpm with uvx --from copilot-plugin-manager cpm in the examples below.

Initialize a new project:

cpm init

Add a plugin and a skill:

cpm add spark@copilot-plugins --plugin
cpm add https://github.com/anthropics/skills/tree/main/skills/pdf --skill

Apply the lockfile to disk:

cpm sync

Inspect what is installed:

cpm list
cpm status

Common examples

Install a plugin from a Copilot marketplace registry:

cpm add spark@copilot-plugins --plugin

Registry plugins delegated to copilot plugin install are effectively global installs. Native plugin bundles added from GitHub tree URLs or local paths still honor local vs global scope.

Install a plugin bundle from a GitHub tree URL:

cpm add https://github.com/github/awesome-copilot/tree/main/plugins/testing-automation --plugin

Install a skill from GitHub:

cpm add https://github.com/anthropics/skills/tree/main/skills/pdf --skill

Inspect one asset in detail:

cpm show testing-automation --plugin

See the consolidated view of manifest, lockfile, and installed state:

cpm overview

Core commands

Command What it does
cpm init Create a new cpm.toml and cpm.lock
cpm add Add an asset to the manifest and resolve it
cpm sync Install everything recorded in cpm.lock
cpm update Update one or all managed assets
cpm remove Remove a managed asset
cpm lock Resolve without installing
cpm reset Remove managed state and/or installed assets
cpm overview Show the combined manifest, lockfile, and disk view
cpm list List installed assets
cpm show Show full details for a single asset
cpm tree Show the dependency tree
cpm doctor Verify installed files match the lockfile
cpm status Show drift between manifest, lockfile, and disk

How cpm works

  • cpm.toml records the assets you want
  • cpm.lock records the resolved versions and hashes
  • cpm sync materializes those assets into .github/ for local scope or ~/.copilot/ for global scope
  • concrete GitHub file and tree sources are fetched directly by cpm
  • delegated Copilot plugin installs are used where the Copilot CLI is the installer of record

Documentation

License

See LICENSE-MIT and LICENSE-APACHE.

Metadata

Release files for copilot-plugin-manager 0.2.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for copilot-plugin-manager 0.2.2
File Size Uploaded
copilot_plugin_manager-0.2.2.tar.gz 204.4 kB Details

Built distributions (wheels)

Table of built distributions (wheels) for copilot-plugin-manager 0.2.2
File Interpreter ABI Platform
copilot_plugin_manager-0.2.2-py3-none-win_amd64.whl Python 3 none Windows x86-64 Details
copilot_plugin_manager-0.2.2-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl Python 3 none Linux glibc 2.17+ x86-64 Details
copilot_plugin_manager-0.2.2-py3-none-macosx_11_0_arm64.whl Python 3 none macOS 11.0+ ARM64 Details

Total release size: 24.7 MB

Release files / copilot_plugin_manager-0.2.2.tar.gz

Download URL copilot_plugin_manager-0.2.2.tar.gz
Size 204.4 kB
Tags Source
SHA-256 checksum
How to use checksums
00fe95076d7e0326f2f942b285128a54b814dcff2b838fae78ec8d6cf6fb73eb
BLAKE2b-256 checksum
How to use checksums
1ded3a91e37a7f1eaee84631f4526216c027fec3f916114fbac84d30268e9d52
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Mar 31, 2026.

Transparency log

Release files / copilot_plugin_manager-0.2.2-py3-none-win_amd64.whl

Download URL copilot_plugin_manager-0.2.2-py3-none-win_amd64.whl
Size 8.2 MB
Tags Python 3 Windows x86-64
SHA-256 checksum
How to use checksums
59fdc4eedab5b2d53f6b030832ebe279e3a21a2f709f848b38ec5f028a00ec69
BLAKE2b-256 checksum
How to use checksums
5dd71f7b282590e8dc473d924015fa461c9aa1cc87d0c804e3f0b054e3dc3c6b
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Mar 31, 2026.

Transparency log

Release files / copilot_plugin_manager-0.2.2-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl

Download URL copilot_plugin_manager-0.2.2-py3-none-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
Size 8.4 MB
Tags Linux glibc 2.17+ x86-64 Python 3
SHA-256 checksum
How to use checksums
7df5888e1c4854dcd755e47cc8562961a83eb0f9342dc21edad50ea14a08a66f
BLAKE2b-256 checksum
How to use checksums
661a0fc2d8df11bdc34df59485c14ca065287497fef5807017b277123cbb354a
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Mar 31, 2026.

Transparency log

Release files / copilot_plugin_manager-0.2.2-py3-none-macosx_11_0_arm64.whl

Download URL copilot_plugin_manager-0.2.2-py3-none-macosx_11_0_arm64.whl
Size 7.8 MB
Tags Python 3 macOS 11.0+ ARM64
SHA-256 checksum
How to use checksums
c754edd78ea172742a0500288b902122dfb8ee4ca6961afd322c6d7fb956cb9e
BLAKE2b-256 checksum
How to use checksums
1938f79e8f73d9a0e18f624b1a0be5c78f2866ece59eafd0f34f5f258467ed7f
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/6.1.0 CPython/3.13.7

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Mar 31, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.2.2 This release

4 release files

0.2.1

4 release files

0.1.4

2 release files

0.1.3

2 release files

0.1.2

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page