convert-plugin-to-apm

convert-plugin-to-apm is a skill for Claude Code from richfrem/agent-plugins-skills. It costs 53 tokens per session (435 once invoked), scanned A, original, MIT.

A migration tool for adding APM package management and governance to an existing Claude, Copilot, or other agent plugin. It supports adding an overlay, using a hybrid layout, or fully converting the package.

In plain words
What is it for?
Use it to add APM metadata and governance, introduce new APM-native assets, or migrate plugin components into a complete APM structure.
Why use it?
It lets an existing plugin adopt package checks and management without automatically disrupting its current layout.

Skill for Claude Code

Written for Claude Code: allowed-tools in frontmatter. Also seen: mentions Claude Code.

Needs its repository: it runs a file that does not travel with it, so clone the repository first. The line is python scripts/validate_apm_package.py --path <target-path>.

Part of the agent-scaffolders plugin — 33 skills shipped together

Good fit Use it to add APM metadata and governance, introduce new APM-native assets, or migrate plugin components into a complete APM structure.

Compare 6 skills from other repositories ↓
Install

Getting it into your agent

It runs from inside its repository, so the clone comes first — what it calls does not travel with the file alone.

Clone the repo
git clone --depth 1 https://github.com/richfrem/agent-plugins-skills
agentmods
npx agentmods add skills/richfrem/agent-plugins-skills/convert-plugin-to-apm

Made for: Claude Code.

Or install agent-scaffolders, the plugin that ships this one along with the rest of its 33 skills.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for convert-plugin-to-apm

README.md
[![agentmods](https://agentmods.dev/badge/skills/richfrem/agent-plugins-skills/convert-plugin-to-apm.svg)](https://agentmods.dev/skills/richfrem/agent-plugins-skills/convert-plugin-to-apm)
Your own site
<a href="https://agentmods.dev/skills/richfrem/agent-plugins-skills/convert-plugin-to-apm"><img src="https://agentmods.dev/badge/skills/richfrem/agent-plugins-skills/convert-plugin-to-apm.svg" alt="Measured on agentmods" height="20"></a>
Per session 53 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 435 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00053 $0.00435
Opus 5 $0.00026 $0.00217
Sonnet 5 $0.00011 $0.00087
Haiku 4.5 $0.00005 $0.00044

Measured 5d ago against content hash 4169ffd4efaa, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-08, from the pricing page.

Security

Grade A, and why

convert-plugin-to-apm scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.

The scan reads SKILL.md. This mod also ships 1 executable file (scripts/migrate_to_apm.py), listed below but not scanned — reading those needs a real analyzer, not pattern matching.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

plugins/agent-scaffolders/skills/convert-plugin-to-apm/SKILL.md · 46 lines

What it actually says

convert-plugin-to-apm Skill 🔄

Overview

This skill implements the Overlay-First migration strategy. It allows existing plugins to gain APM governance without the "repackaging tax" of moving files, unless explicitly requested.

Migration Modes

1. Overlay Mode (Default)

Use when: The plugin is active and its current layout is preferred.

  • Action: Add apm.yml and docs/governance.md to the root.
  • Benefit: Zero disruption to existing npx skills or Claude Code workflows.

2. Hybrid Mode

Use when: You want to keep the plugin layout but start adding new APM-native assets.

  • Action: Add .apm/ for new governance assets; keep existing primitives in place.

3. Full Conversion

Use when: You want a clean, APM-native package structure.

  • Action: Create a new directory and migrate all primitives into .apm/.
  • Note: Always preserve the original plugin untouched.

🎯 Primary Directive

Do not force .apm/ as the new source of truth unless explicitly requested.

Validation & Audit

After conversion, run:

python scripts/validate_apm_package.py --path <target-path>

Mapping Rules (Full Mode)

  • .claude-plugin/plugin.json -> Metadata for apm.yml
  • skills/* -> .apm/skills/*
  • agents/* -> .apm/agents/*
  • commands/* -> .apm/prompts/* (APM standard)
  • hooks/hooks.json -> .apm/hooks/hooks.json
Files

What ships with it

5 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 5d ago First seen · 46 lines · 53 tokens per session scan A 4169ffd4efaa

Subscribe to this mod's changes

convert-plugin-to-apm is a skill published in the GitHub repository richfrem/agent-plugins-skills (6 stars, last pushed today), licensed MIT. It adds 53 tokens to every session and 435 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.