LPM CLI

lpm skills

Publish, install, inspect, and manage package and standalone agent skills.

lpm skills handles two skill systems: skills published with @lpm.dev/* packages and standalone skills added from GitHub or a local directory.

Quickstart

# Install guidance published with an LPM.dev package
lpm skills add @lpm.dev/owner.package --dry-run
lpm skills add @lpm.dev/owner.package --yes

# Validate guidance before publishing your own package
lpm skills validate

# Add a standalone skill from GitHub
lpm skills add owner/repository

Choose a workflow

GoalSourceMain commands
Use guidance shipped by an LPM.dev package@lpm.dev/owner.packagelpm install, lpm skills add, lpm skills clean
Publish guidance with your own LPM.dev packageFlat .lpm/skills/*.md fileslpm skills validate, lpm publish
Manage a standalone agent skillGitHub or a local directorylpm skills add, update, enable, disable, remove

For the ownership, storage, and security model behind these workflows, see AI agent skills.

Install skills from an LPM.dev package

Direct @lpm.dev/* dependencies install their published skills automatically:

lpm install @lpm.dev/owner.package

The package-owned set is materialized in .lpm/skills/owner.package/. It stays separate from agent-specific skill directories and is reconciled when the package is installed, upgraded, or removed.

Fetch or preview one package explicitly with lpm skills add:

lpm skills add @lpm.dev/owner.package --list
lpm skills add @lpm.dev/owner.package --dry-run
lpm skills add @lpm.dev/owner.package --yes

Package sources are installed as one set. Standalone-only flags such as --skill, --agent, --project, --global, --copy, and --full-depth are rejected for @lpm.dev/* inputs.

Configure automatic installation

Package skill reconciliation is enabled by default. Open the package-skills setting directly, or set it non-interactively:

lpm config lpm-skills
lpm config lpm-skills --set false
lpm config lpm-skills --set true

You can also open the full configuration wizard and choose LPM.dev package skills, then choose enabled or disabled:

lpm config

Use --no-skills on lpm install, lpm add, or lpm ci to opt out once. Use --skills to override a disabled preference once. The setting does not delete existing package skills and does not affect explicit lpm skills add commands.

Clean installed package skills

Preview cleanup before applying it:

lpm skills clean --dry-run
lpm skills clean
lpm skills clean --yes

clean removes only package directories whose files and digests exactly match an LPM CLI ownership manifest. It preserves publisher-authored .lpm/skills/*.md files, untracked or modified content, invalid manifests, symlinks, standalone managed content, and agent links.

In a terminal, clean shows the package sets, file count, and size, then asks for confirmation with No as the default. Non-interactive cleanup requires --yes after reviewing --dry-run. Run lpm install to restore removed package sets.

Publish skills with an LPM.dev package

Package publishers author direct Markdown files under .lpm/skills/:

.lpm/
└── skills/
    ├── usage.md
    └── migration.md

Nested publisher paths such as .lpm/skills/guides/usage.md are invalid. Each file needs YAML frontmatter and a Markdown body:

---
name: package-usage
description: Use the package through its supported public API.
version: "1.4.0"
globs:
  - "src/**/*.ts"
---

# Package usage

Import the public client, initialize it once, and reuse that instance. Follow the package's documented error handling and configuration conventions when changing an existing integration.

Use the LPM package-skill authoring guide for help designing the files. You can install it as a standalone skill:

lpm skills add lpm-dev/lpm-guide

Validate locally, then publish:

lpm skills validate
lpm publish

validate checks the same publisher contract enforced by the LPM.dev Registry:

RuleRequirement
LocationDirect .md files under .lpm/skills/
CountAt most 10 skills
File sizeAt most 15 KB per skill
Total sizeAt most 100 KB
FrontmatterRequired name and description; optional version and globs
NameLowercase letters, numbers, and hyphens
Description10–500 characters
BodyAt least 100 characters
SecurityNo blocked shell injection, exfiltration, prompt injection, or destructive filesystem patterns

Validation exits non-zero when any rule fails. If the project also consumes LPM.dev package skills, manifest-owned .lpm/skills/<owner.package>/ directories are ignored by publisher validation and excluded from the publish tarball. Other nested Markdown is rejected. When package.json > files is restrictive, lpm publish adds .lpm/skills before creating the tarball.

Set optional version to the package release the guidance was authored for. The LPM.dev Registry stores it independently from the release currently carrying the skill, and the LPM CLI preserves it when materializing installed guidance. Leaving an older value in place makes intentionally stale guidance visible instead of silently relabeling it as current.

Add standalone skills from GitHub or local sources

Standalone inputs support GitHub URLs, GitHub owner/repository shorthand, and local directories:

lpm skills add vercel-labs/skills --skill find-skills
lpm skills add https://github.com/vercel-labs/agent-skills --skill web-design-guidelines
lpm skills add ./team-skills --skill release-notes --agent codex --project

Remote standalone inputs must resolve to GitHub. When a catalog helps you discover a skill, pass the underlying GitHub repository or tree URL to the LPM CLI.

In a terminal, add opens a wizard for source, skill selection, project or global scope, compatible agent targets, security review, and confirmation. For scripts, provide the selection flags and --yes after reviewing --dry-run:

lpm skills add owner/repository \
  --skill release-notes \
  --agent codex \
  --project \
  --dry-run

lpm skills add owner/repository \
  --skill release-notes \
  --agent codex \
  --project \
  --yes

lpm skills install remains a compatibility alias for lpm skills add. Use add in new scripts.

FlagEffect
--skill <name>Select a standalone skill. Repeat it, or use --skill '*' for all discovered skills.
--agent <target>Select codex, claude-code, or cursor. Repeat for multiple targets.
--project / --globalChoose standalone canonical storage scope.
--copyCopy standalone files to targets instead of linking them.
--listDiscover and preview a source without installing it.
--full-depthSearch beyond standard skill directory layouts.
--dry-runShow planned filesystem changes without writing them.
--yesConfirm a non-interactive mutation.

Warning-level security findings remain installable after explicit confirmation. Block-level findings stop add or update before any managed content or agent targets are written.

Inspect all skills

lpm skills list
lpm skills list --kind package
lpm skills list --kind managed --agent codex
lpm skills view owner.package/usage
lpm skills view release-notes

The unified inventory distinguishes ownership:

CategoryMeaning
packageSkills installed from LPM.dev packages into .lpm/skills/<owner.package>/.
managedStandalone skills added through lpm skills add.
externalExisting agent-directory skills not managed by the LPM CLI.

view reports source, integrity, estimated context size, security findings, and agent-target health. Add --global to include global managed and external locations.

Manage standalone skills

lpm skills doctor
lpm skills update release-notes --dry-run
lpm skills update release-notes --yes
lpm skills disable release-notes --agent cursor --yes
lpm skills enable release-notes --yes
lpm skills remove release-notes --yes
lpm skills prune --dry-run

update re-resolves the source, shows a bounded content diff and new security findings, then refreshes canonical content and recorded targets. disable removes selected target links while retaining canonical content. remove removes targets and deletes canonical content when no targets remain. prune previews and removes orphaned managed links and stale state records.

update, remove, enable, and disable accept skill selectors or --all, plus --global, --dry-run, and --yes. remove, enable, and disable also accept repeated --agent filters. prune accepts --global, --dry-run, and --yes. These commands do not mutate package-installed skills.

Local dashboard

lpm skills dashboard
lpm skills dashboard --read-only
lpm skills dashboard --no-open
lpm skills dashboard --port 4401

dashboard opens an authenticated browser view of every discovered project and global skill. lpm skills ui is an alias. Use the source tabs to filter the combined inventory without restarting the command with a scope flag.

Select a skill to inspect its rendered Markdown, exact raw source, bounded file tree, metadata, context estimate, integrity, and security status. Package and external skills are inspection-only. Managed standalone skills expose enable, disable, update, and remove through a reviewable preview-and-apply plan. --read-only disables all mutations.

The server binds only to 127.0.0.1. Omit --port to select a free port, or request an exact port. --no-open prints the authenticated URL. The URL fragment carries the local session token; the dashboard captures and removes it from the address bar after startup. Keep the command running while using the dashboard and press Ctrl+C to stop it.

JSON and CI

Global --json emits one structured result per command. Inventory includes total counts and package, managed, and external counts. Use --dry-run --json to capture a mutation plan, then repeat the command with --yes. No-op validation, cleanup, and prune operations still emit successful zero-count results.

See also