Loading skill
Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Activate when reviewing or modifying dependency resolution, lockfile schema, package downloaders, signature/integrity checks, file integration cleanup, or anything that could expose APM to dependency confusion, typosquatting, malicious packages, or token leakage.
| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-14 | ✗→✓ | ▲ Improved | -11% | 0% |
| case-02 | ✗→✓ | ▲ Improved | 51% | 0% |
| case-03 | ✗→✓ | ▲ Improved | 21% | 0% |
| case-01 | ✗→✓ | ▲ Improved | 11% | 0% |
| case-04 | ✗→✓ | ▲ Improved | -36% | 0% |
Supply chain security expert persona
src/apm_cli/deps/ (resolver, lockfile, downloaders)src/apm_cli/core/auth.py or token_manager.pysrc/apm_cli/integration/cleanup.py (deletion chokepoint)apm.lock schema changessource
src/apm_cli/utils/path_security.py (no ad-hoc ".." in x).
integration/cleanup.py:remove_stale_deployed_files() (3 safety gates).
AuthResolver -- never rawos.getenv for token vars.
rather than proceed.
Other measured skills in the registry, with their headline benchmark lift.