Install architectures, not dependencies.
Source code, AI rules and MCP servers, injected into your repo and pinned to a commit. Your AI already knows how to use it.
curl -fsSL https://genpm.net/install.sh | shirm https://genpm.net/install.ps1 | iexgenpm add @core/authgenpm mcp setupThen ask your agent: Add GitHub login to this project with genpm
Three layers. One commit.
Every package carries its code, the rules your AI needs to use it, and the MCP servers it talks to. All three pass through the same SHA check.
Code you own
Lands in src/, not in node_modules. You see it in your diff, edit it and commit it.
Context your AI gets
An AGENTS.md per module, loaded only when your agent works in that folder.
Connections, ready
The MCP servers a module needs, declared in its manifest. Added only with your consent.
Start with @core
No packages yet. Be the first to publish one.
Installs
Search. Inspect. Inject.
Search
Find a module by need, from the web, the CLI or your AI.
genpm search stripeInspect
Read the exact files, the AI rules and the commit before anything touches your repo.
genpm info @core/billingInject
Code lands in src/, rules go where your IDE reads them, and the lockfile pins the SHA.
genpm add @core/billingConnect GenPM to your editor
One MCP server. Your agent searches, inspects and installs, and asks you before adding anything outside your code.
claude mcp add genpm -- genpm mcp serve{ "mcpServers": { "genpm": { "command": "genpm", "args": ["mcp", "serve"] } } }{ "servers": { "genpm": { "type": "stdio", "command": "genpm", "args": ["mcp", "serve"] } } }{ "mcpServers": { "genpm": { "command": "genpm", "args": ["mcp", "serve"] } } }[mcp_servers.genpm] command = "genpm" args = ["mcp", "serve"]
Or run genpm mcp setup and GenPM writes the config for every client it detects.
No genpm binary? Use npx -y @genpm/mcp instead (needs Node.js).
What you reviewed is what gets installed.
Pinned to a SHA
Tags resolve to a 40-character commit, verified after every fetch. Never a branch.
Zero scripts
GenPM has no lifecycle hooks. Nothing from a package runs on your machine.
Rules scanned
Every AI rule file is checked for prompt injection before it is listed.
Publish your architecture in 60 seconds.
Tag a release, add a genpm.json and an AGENTS.md. The registry stores metadata only; your code stays on GitHub.