Reference

Distribution and upgrades

TL;DRDistribution is pinned to an immutable release, never a mutable branch. Every channel downloads the same tagged tarball and verifies its sha256 before extracting anything.

Principle

Distribution is pinned to an immutable release, never a mutable branch. Every channel ultimately downloads the same tagged GitHub Release tarball and verifies its sha256 against the release’s checksums.txt before extracting anything. The release is built and attested by CI; the installers are thin.

Channels

Channel Who it is for What it does Never
git clone Contributors Clone the repo and run bash install.sh -
Pinned curl bootstrap One-line install (Linux, macOS, Git Bash) Downloads the pinned tarball, verifies the checksum, links the aas CLI Fetches main
aas CLI Day-to-day use after bootstrap install, upgrade, doctor, uninstall Fetches main
npm wrapper Node-adjacent users npx @juandelossantos/another-agent-skills install Ships no payload

Install with the bootstrap

curl -fsSL https://github.com/juandelossantos/another-agent-skills/releases/latest/download/bootstrap.sh | bash

bootstrap.sh --version vX.Y.Z pins an exact release, --dry-run prints every action without writing anything, and --uninstall removes the install root and the aas symlink. The install root is ${XDG_DATA_HOME:-$HOME/.local/share}/another-agent-skills, overridable with AAS_HOME.

The aas CLI

aas install --agents auto     # activate in the current project
aas doctor                    # environment report (agents, plugin state)
aas upgrade                   # self-update from the latest pinned release
aas uninstall                 # remove the CLI, install root, and PATH entry

--agents auto|all|<list> selects which detected agents to install into. auto prompts only when stdin is a TTY, so CI never blocks.

npm

npx @juandelossantos/another-agent-skills install
npx @juandelossantos/another-agent-skills install --version v6.4.0

The npm package contains only cli.js and a README. It downloads the release tarball and checksums.txt, verifies the sha256 with node:crypto, and delegates to the release’s own bootstrap.sh, so install logic lives in exactly one place. It is published via OIDC trusted publishing (no stored token).

Release automation

Pushing a v* tag triggers a workflow that builds the tarball plus checksums.txt, attests build provenance, and publishes the GitHub Release. A second workflow syncs the npm version from VERSION, skips if that version already exists, and publishes through OIDC Trusted Publishing with no stored token. Verify a release locally:

gh attestation verify dist/another-agent-skills-vX.Y.Z.tar.gz --repo juandelossantos/another-agent-skills

Upgrades

aas upgrade    # self-update to the latest pinned release (atomic)

aas upgrade resolves the latest release and installs it atomically (staging directory plus rename), so a partial extraction can never leave a broken install. For a project that pins a framework version, a non-blocking drift advisory appears in pre-commit and doctor when the installed version differs from the project’s .aas/config. Run aas upgrade, then init-agents --repair to migrate.

The npm account must exist before a Trusted Publisher can be configured, so the first publish is a one-time manual step. After that, releases publish with a short-lived OIDC token.

Edit this page