| Skill | Added | Review |
|---|---|---|
apm-usage packages/apm-guide/.apm/skills/apm-usage/SKILL.md Activate when the user asks about APM (Agent Package Manager): installing, configuring, authoring, or troubleshooting AI-agent packages, dependencies, compilation, MCP servers, policy, or any `apm` CLI command. | 67 67 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 634f7b6 | |
supply-chain-security .apm/skills/supply-chain-security/SKILL.md Activate when reviewing or modifying dependency resolution, lockfile schema, package downloaders, signature/integrity checks, file integration cleanup, or anything that could expose APM to dependency confusion, typosquatting, malicious packages, or token leakage. | 75 75 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 634f7b6 | |
python-architecture .apm/skills/python-architecture/SKILL.md Activate when creating new modules, refactoring class hierarchies, introducing design patterns, or making changes spanning 3+ files in the APM CLI codebase. | 71 71 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 634f7b6 | |
oss-growth .apm/skills/oss-growth/SKILL.md Activate for OSS adoption work -- README conversion surfaces, quickstart, templates, release announcements, contributor funnel, story angles -- and any update to the maintained growth strategy at WIP/growth-strategy.md. | 65 65 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 634f7b6 | |
docs-sync .apm/skills/docs-sync/SKILL.md Use this skill whenever a pull request is opened, reopened, or synchronized in microsoft/apm to assess whether and how the documentation corpus must change to stay truthful with the proposed code change. Activate even when the PR title or body says nothing about docs -- the skill must run on every PR to detect silent drift between code and docs. Classifies impact as no-change, in-place edit (one to a few paragraphs), or structural change (new page or TOC reshape), then orchestrates a CDO + doc-writer + python-architect + editorial-owner + growth-hacker loop to produce a patch-ready advisory. Does NOT review code quality, security, or test coverage. Does NOT auto-merge or auto-push doc edits. | 69 69 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 634f7b6 | |
docs-corpus-audit .apm/skills/docs-corpus-audit/SKILL.md Use this skill to run a holistic regrounding pass on the entire microsoft/apm documentation corpus against current source code, page-by-page, and emit surgical fixes for stale claims. Activate when the maintainer wants a WHOLE-CORPUS audit (not per-PR review) -- typical triggers include "audit the docs", "reground the corpus", "check every page against code", "pre-release docs sweep", "the docs have drifted everywhere", or "we just reshaped the TOC, find dead links". Wave-batched and S7-verified; scales to the full ~112-page corpus in ~10 minutes wall-time. This is a SIBLING to docs-sync, not a replacement: docs-sync is per-PR (triggered by a diff); this skill is per-corpus (triggered by a maintainer ask). They share agent personas, schemas, and the docs index, but their triggers MUST NOT collide. Does NOT auto-merge, does NOT push without maintainer review, and does NOT replace per-PR drift detection. | 74 74 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 634f7b6 | |
devx-ux .apm/skills/devx-ux/SKILL.md Activate when designing or modifying CLI command surfaces, command help text, install/init/run flows, error wording, or first-run experience in the APM CLI -- even when the user does not say "UX" explicitly. | 65 65 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 634f7b6 | |
cli-logging-ux .apm/skills/cli-logging-ux/SKILL.md Use this skill when editing or creating CLI output, logging, warnings, error messages, progress indicators, or diagnostic summaries in the APM codebase. Activate whenever code touches console helpers (_rich_success, _rich_warning, _rich_error, _rich_info, _rich_echo), DiagnosticCollector, STATUS_SYMBOLS, CommandLogger, or any user-facing terminal output — even if the user doesn't mention "logging" or "UX" explicitly. | 68 68 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 634f7b6 | |
auth .apm/skills/auth/SKILL.md Activate when code touches token management, credential resolution, git auth flows, GITHUB_APM_PAT, ADO_APM_PAT, AuthResolver, HostInfo, AuthContext, or any remote host authentication -- even if 'auth' isn't mentioned explicitly. | 73 73 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 634f7b6 | |
apm-strategy .apm/skills/apm-strategy/SKILL.md Activate for changes to project positioning, release communication, community-facing artifacts, or breaking-change decisions in microsoft/apm. Triggers on README, MANIFESTO, PRD, CHANGELOG, release workflows, and issue templates. | 61 61 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 634f7b6 | |
apm-spec-guardian .apm/skills/apm-spec-guardian/SKILL.md Use this skill to run a four-panel adversarial advisory review on any pull request that touches the OpenAPM specification artifact (docs/src/content/docs/specs/openapm-*.md), its inline / sidecar JSON Schemas (docs/src/content/docs/specs/schemas/*.schema.json), or the conformance fixture seed (tests/fixtures/spec-conformance/**). The panel fans out to four spec-ecosystem reviewers (swagger-openapi-editor, oci-distribution-editor, pkgmgr-registry-contract-editor, w3c-tag-architect), each running in its own agent thread, and a spec-editor synthesizer that produces a fold-now / defer-v0.1.1 / defer-v0.2 / reject list plus a ship decision keyed off a 1..10 shocked_meter scale. The orchestrator is the sole writer to the PR: ONE consolidated comment, no verdict labels, no merge gating. The panel is advisory -- it surfaces findings, prioritizes folds, and renders a ship recommendation that the maintainer weighs. | 69 69 Impact — No eval scenarios have been run Securityby High Do not use without reviewing Version: 634f7b6 | |
supply-chain-security .agents/skills/supply-chain-security/SKILL.md Activate when reviewing or modifying dependency resolution, lockfile schema, package downloaders, signature/integrity checks, file integration cleanup, or anything that could expose APM to dependency confusion, typosquatting, malicious packages, or token leakage. | 72 72 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 634f7b6 | |
shepherd-driver .agents/skills/shepherd-driver/SKILL.md Use only as the composed drive-to-merge stage of an APM batch orchestrator (batch-bug-shepherd, apm-issue-autopilot) that has already selected ONE open pull request in microsoft/apm. Do NOT use for user-facing requests to triage issues, sweep a queue, or open PRs -- the parent orchestrator owns those. Spawn one shepherd-driver subagent per PR: it classifies copilot-pull-request-reviewer[bot] inline review, runs the apm-review-panel, folds (by default) every recommendation inside the PR's stated scope, pushes to the head branch or a superseding PR that preserves authorship via commit trailers, watches CI to green, and iterates under fixed caps until ready-to-merge, advisory-with-deferred, superseded, or blocked. Also provides the cross-PR conflict-resolution and mergeability-gate phase. This is NOT a standalone entrypoint. | 73 73 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 634f7b6 | |
python-architecture .agents/skills/python-architecture/SKILL.md Activate when creating new modules, refactoring class hierarchies, introducing design patterns, or making changes spanning 3+ files in the APM CLI codebase. | 59 59 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 634f7b6 | |
pr-description-skill .agents/skills/pr-description-skill/SKILL.md Use this skill to write the PR description (PR body) for any pull request opened against microsoft/apm. Produces one self-sufficient GitHub-Flavored Markdown artifact: TL;DR, Problem (WHY), Approach (WHAT), Implementation (HOW), 1-3 validated mermaid diagrams, explicit trade-offs, validation evidence, and a How-to-test section -- with every WHY-claim backed by a verbatim quote from PROSE or Agent Skills. Activate when the user asks to "write a PR description", "draft a PR body", "open a PR", "fill in the PR template", or any equivalent. | 75 75 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 634f7b6 | |
oss-growth .agents/skills/oss-growth/SKILL.md Activate for OSS adoption work -- README conversion surfaces, quickstart, templates, release announcements, contributor funnel, story angles -- and any update to the maintained growth strategy at WIP/growth-strategy.md. | 66 66 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 634f7b6 | |
docs-sync .agents/skills/docs-sync/SKILL.md Use this skill whenever a pull request is opened, reopened, or synchronized in microsoft/apm to assess whether and how the documentation corpus must change to stay truthful with the proposed code change. Activate even when the PR title or body says nothing about docs -- the skill must run on every PR to detect silent drift between code and docs. Classifies impact as no-change, in-place edit (one to a few paragraphs), or structural change (new page or TOC reshape), then orchestrates a CDO + doc-writer + python-architect + editorial-owner + growth-hacker loop to produce a patch-ready advisory. Does NOT review code quality, security, or test coverage. Does NOT auto-merge or auto-push doc edits. | 69 69 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 634f7b6 | |
docs-impact-localizer .agents/skills/docs-impact-localizer/SKILL.md Use this skill to translate a classifier's in-place verdict into a precise, page-by-page work plan for the docs-sync panel. Activate after docs-impact-classifier returns verdict in_place; reads the candidate page list, fetches the actual page contents, narrows scope to specific sections within each page, and emits the per-page task brief the panel fans out against. | 75 75 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 634f7b6 | |
docs-impact-classifier .agents/skills/docs-impact-classifier/SKILL.md Use this skill to classify the documentation impact of a pull request diff, returning one of three verdicts -- no-change, in-place edit, or structural change -- with bounded LLM cost. Activate as a sibling skill of docs-sync; the orchestrator calls this first, before any panel spawn, to keep cost floor at 1 LLM call when no docs work is needed. Reads .apm/docs-index.yml as the corpus map; never reads the full corpus. | 75 75 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 634f7b6 | |
docs-impact-architect .agents/skills/docs-impact-architect/SKILL.md Use this skill when the docs-impact-classifier returns a structural verdict, signalling that the documentation TOC must change to accommodate the PR. Proposes TOC deltas (new pages, moves, merges) and emits new-page outline stubs that the doc-sync panel later fleshes out. Holds the 3-promise narrative (consume / produce / govern) and the persona ramps as hard constraints. | 68 68 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 634f7b6 | |
docs-corpus-audit .agents/skills/docs-corpus-audit/SKILL.md Use this skill to run a holistic regrounding pass on the entire microsoft/apm documentation corpus against current source code, page-by-page, and emit surgical fixes for stale claims. Activate when the maintainer wants a WHOLE-CORPUS audit (not per-PR review) -- typical triggers include "audit the docs", "reground the corpus", "check every page against code", "pre-release docs sweep", "the docs have drifted everywhere", or "we just reshaped the TOC, find dead links". Wave-batched and S7-verified; scales to the full ~112-page corpus in ~10 minutes wall-time. This is a SIBLING to docs-sync, not a replacement: docs-sync is per-PR (triggered by a diff); this skill is per-corpus (triggered by a maintainer ask). They share agent personas, schemas, and the docs index, but their triggers MUST NOT collide. Does NOT auto-merge, does NOT push without maintainer review, and does NOT replace per-PR drift detection. | 74 74 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 634f7b6 | |
devx-ux .agents/skills/devx-ux/SKILL.md Activate when designing or modifying CLI command surfaces, command help text, install/init/run flows, error wording, or first-run experience in the APM CLI -- even when the user does not say "UX" explicitly. | 65 65 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 634f7b6 | |
cut-release .agents/skills/cut-release/SKILL.md Use this skill to cut an APM release from the current worktree: assess whether the cycle since the last tag warrants a patch or minor bump (semver discipline against the merged-since-last-tag diff), sanitize the [Unreleased] CHANGELOG block into a dated version block with one concise "so what" entry per merged PR (drop internal-only churn, consolidate duplicates), bump pyproject.toml + uv.lock, run the CI-mirror lint chain, and open the release PR. Activate on "ship a release", "cut v0.x", "release prep", "bump and PR", "open release PR", "what kind of release do we need", or any phrasing that ends in opening a release PR -- even when the user does not say "skill". Stops BEFORE tagging; tagging stays a human gate that triggers the release workflow. Refuses to bump to a major (>= 1.0.0) version without explicit operator confirmation. | 79 79 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 634f7b6 | |
cli-logging-ux .agents/skills/cli-logging-ux/SKILL.md Use this skill when editing or creating CLI output, logging, warnings, error messages, progress indicators, or diagnostic summaries in the APM codebase. Activate whenever code touches console helpers (_rich_success, _rich_warning, _rich_error, _rich_info, _rich_echo), DiagnosticCollector, STATUS_SYMBOLS, CommandLogger, or any user-facing terminal output — even if the user doesn't mention "logging" or "UX" explicitly. | 72 72 Impact — No eval scenarios have been run Securityby Passed No findings from the security scan Version: 634f7b6 | |
batch-bug-shepherd .agents/skills/batch-bug-shepherd/SKILL.md Use this skill to drive a batch of suspected bugs in microsoft/apm from raw issue list to mergeable PR queue. Fan out one triage subagent per issue (LEGIT / UNCLEAR / FIXED-AT-HEAD), gate every legit bug against PRINCIPLES.md via an apm-ceo strategic-alignment pass, cross-reference legit issues against open PRs, then open a fix PR (TDD + mutation-break gate) for greenfield bugs. Drive every PR -- community in-flight and own fix alike -- to mergeable by composing the shepherd-driver skill: one driver per PR runs the review panel, folds non-blocking recommendations, pushes (preserving author), and watches CI to green. Re-probe mergeability and resolve conflicts via shepherd-driver. Maintain a plan.md ground-truth table as canonical state. Activate when the maintainer asks to triage issues, sweep the bug queue, shepherd bug-flagged issues, run a weekly community sweep, or drive in-flight community PRs to merge -- even if "shepherd" or "batch" is not named. | 73 73 Impact — No eval scenarios have been run Securityby Low Low-risk findings worth noting Version: 634f7b6 |