Getting Started
This guide walks through installing asrpm, configuring it for your chain of choice, and running your first commands.
Prerequisites
- macOS or Linux (Windows builds are not currently published)
- For
go installor building from source: Go 1.25.0 or later - For authoring commands (
register,publish): a Foundry keystore at~/.foundry/keystores/<name>or anASRPM_PRIVATE_KEYenvironment variable
Installation
Homebrew (macOS, Linux)
brew install vorpalengineering/tap/asrpm
Prebuilt binary
Download a tarball for your platform from the GitHub releases page and place the extracted asrpm binary somewhere on your PATH.
Go install
go install github.com/vorpalengineering/asrpm/cmd/asrpm@latest
Build from source
git clone https://github.com/vorpalengineering/asrpm
cd asrpm
go build -o asrpm ./cmd/asrpm
Quick Start
asrpm ships with a Sepolia RPC endpoint and registry address. The examples use skill ID 0; they require the configured RPC and registry to be available and that skill to exist.
Inspect a skill
resolve is read-only and requires no signer. It fetches the manifest, checks the manifestHash commitment when available, and prints the result. An unset or unreadable commitment is reported without aborting; a mismatched nonzero hash is rejected.
asrpm resolve 0
Add --json to emit the raw manifest, or --verbose for full URIs and integrity values.
Install a skill
install resolves the skill, checks the nonzero registry commitment and the selected target’s integrity hash, and writes the matching target's body to ~/.claude/skills/<sanitized-name>/SKILL.md:
asrpm install 0
# Restart Claude Code to load the new skill.
The default install target is claude-code (v1 supports this target only). Add --scope project to install under the current project's .claude/skills/ directory instead of the user-level location.
List installed skills
asrpm list
asrpm list --json
Refresh a skill
update re-resolves a previously installed skill and rewrites its body if the selected target’s integrity value has changed.
asrpm update 0
If the recorded target integrity is unchanged, update is a no-op; it does not rehash the local file or use the version string to decide whether to update.
Uninstall
asrpm uninstall <name|skillId>
The CLI looks up the install in the local index. For an unindexed skill, uninstall <name> --force removes ~/.claude/skills/<name>/SKILL.md and removes its directory only if empty. This fallback does not prompt for confirmation.
Configuration
The configuration file lives at ~/.asrpm/config.json and is created on the first asrpm config set … call (mode 0600). Environment variables always override file values. Multiple fields can be set in a single call.
Configuration keys
| Key | Env var | Default | Purpose |
|---|---|---|---|
rpc_url | ASRPM_RPC_URL | https://ethereum-sepolia-rpc.publicnode.com | JSON-RPC endpoint for the target chain |
skill_registry | ASRPM_SKILL_REGISTRY | 0x8239AAbaa1A44338bEeFAAf4C3a373d2a18D5DC4 (Sepolia) | SkillRegistry contract address |
Inspecting current configuration
asrpm config
asrpm config --json
asrpm config get rpc_url
Updating configuration
asrpm config set \
--rpc-url <RPC_URL> \
--skill-registry <SKILL_REGISTRY_ADDRESS>
Pass --registry <addr> on resolve, verify, install, update, uninstall, register, or publish to override the configured registry for a single invocation.
The configuration has no private-key field. RPC URLs may themselves contain provider credentials.
Wallet Handling
asrpm deliberately does not manage its own keystore. Write commands (register, publish) accept signing material from one of two sources, neither of which causes the CLI to persist a plaintext private key.
Foundry keystore (recommended)
Pass --account <name> to load and decrypt ~/.foundry/keystores/<name> after prompting for the password on stdin:
asrpm register \
--manifest path/to/manifest.json \
--uri https://gateway.pinata.cloud/ipfs/<cid> \
--account my-keystore
Use Foundry’s cast wallet commands to create and manage the keystore. asrpm reads and decrypts the selected file when signing a transaction.
Environment variable (CI and local development)
Set ASRPM_PRIVATE_KEY to a raw hex private key. A warning is printed on use.
export ASRPM_PRIVATE_KEY=0x1234567890abcdef...
asrpm register --manifest path/to/manifest.json --uri https://example.com/manifest.json
--account always takes precedence over ASRPM_PRIVATE_KEY when both are present.
Read-only commands (resolve, verify, list) never require a signer.
URI Schemes
Manifests and target bodies must use one of the supported URI schemes:
| Scheme | Notes |
|---|---|
https:// | Recommended for hosted content. |
http:// | Supported but discouraged. |
data: | Inline content (base64 or URL-encoded). Recommended for small bodies; lets the manifest be fully self-contained. |
The ipfs:// scheme is not supported. Use the HTTPS gateway URL your pinning provider serves (e.g. https://gateway.pinata.cloud/ipfs/<cid> or https://ipfs.io/ipfs/<cid>). Gateway choice does not change the hash checks: a nonzero registry commitment authenticates the manifest, and the selected target’s integrity authenticates its body.
Next Steps
- See the CLI Reference for complete command and flag documentation
- See the Manifest Reference for the Skill Manifest File schema
- Read the ERC-8239 specification for protocol details