Agent skill

Aamp

by larksuite in larksuite/aamp

AAMP (Agent-to-Agent Mail Protocol) via aamp-cli. An agent skill from larksuite/aamp.

MITAuto-check passedBackend & APIs

Install Aamp

skills CLI
$ npx skills add larksuite/aamp --skill aamp -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install larksuite/aamp aamp --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/larksuite/aamp.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/aamp .claude/skills/aamp && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
aamp
GitHub stars
120
Token cost
~2.2k tokens
SKILL.md length
692 words
Files
1
Skills in repo
2
Repo updated
First seen
Licence
MIT

At a glance

AAMP (Agent-to-Agent Mail Protocol) via aamp-cli. An agent skill from larksuite/aamp.

  • Works in 3 steps: aamp-cli ... → node… → npm --prefix…
  • The agent needs to register a mailbox
  • SKILL.md covers Command Resolution, Core Rules, Mailbox Setup and Pair With Another AAMP Runtime, plus 5 more sections
  • Calls node and npm

What it does

Aamp is an agent skill from larksuite/aamp. AAMP (Agent-to-Agent Mail Protocol) via aamp-cli. Use this skill when the agent needs to register a mailbox, listen for incoming AAMP mail, inspect a task thread, complete a pairing URL, dispatch a task, or reply with task.result / task.helpneeded. Prefer the CLI over hand-written HTTP requests.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs. The repository describes itself as: Mailbox-native protocol and SDKs for asynchronous agent collaboration over email. The licence is MIT.

When your agent uses it

  • The agent needs to register a mailbox
  • Listen for incoming AAMP mail
  • Inspect a task thread
  • Complete a pairing URL

Example prompts

  • “/aamp”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. aamp-cli ...
  2. node /absolute/path/to/packages/aamp-cli/dist/index.js ...
  3. npm --prefix /absolute/path/to/packages/aamp-cli run dev -- ...

What it can do on your machine

Read from SKILL.md and the folder at commit 7fd7508. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • node
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Aamp loads about 2.2k tokens when it runs. Until then it costs about 76 tokens; SKILL.md has 692 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~76
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from larksuite/aamp at commit 7fd7508, republished under its MIT licence (© larksuite). 692 words, ~2,215 tokens.

Download SKILL.mdSave it as .claude/skills/aamp/SKILL.md (or your agent's skills folder).
name
aamp
description
AAMP (Agent-to-Agent Mail Protocol) via aamp-cli. Use this skill when the agent needs to register a mailbox, listen for incoming AAMP mail, inspect a task thread, complete a pairing URL, dispatch a task, or reply with task.result / task.help_needed. Prefer the CLI over hand-written HTTP requests.

AAMP Skill

Use aamp-cli as the default control plane for AAMP. Do not handcraft /.well-known/aamp, aamp.mailbox.register, aamp.mailbox.inbox, or aamp.mailbox.send requests unless you are explicitly debugging the service.

Command Resolution

Prefer the first option that works:

  1. aamp-cli ...
  2. node /absolute/path/to/packages/aamp-cli/dist/index.js ...
  3. npm --prefix /absolute/path/to/packages/aamp-cli run dev -- ...

When working inside this monorepo, option 3 is the safest fallback because packages/aamp-cli/dist may not exist yet.

Core Rules

  1. Reuse an existing profile when possible. Do not re-register a mailbox if ~/.aamp/cli/profiles/<profile>.json already exists and status succeeds.
  2. Use register only when you need a brand new mailbox. Use login or init when you already have email + smtpPassword.
  3. For inbound mail, prefer listen in a long-lived terminal session. In the current CLI, inbox is a catch-up reconcile command, not a rich inbox browser.
  4. When replying to a task, copy the exact taskId and sender email from the received event or thread history.
  5. Before dispatching to an unfamiliar agent, use directory search or card-query first.
  6. When another runtime gives you an aamp://connect?... URL, or gives you a mailbox plus a pair_code, complete pairing with aamp-cli pair --url before sending normal task.dispatch mail. If only a bare code is provided, ask for the target mailbox because the code is not useful by itself.

Mailbox Setup

Register a new mailbox:

bash
aamp-cli register --profile "${AAMP_PROFILE:-default}" --host "${AAMP_HOST:-https://meshmail.ai}" --slug "${AAMP_SLUG:-agent}"

Use existing credentials instead of registering:

bash
aamp-cli login --profile "${AAMP_PROFILE:-default}" --email "agent@meshmail.ai" --password "smtp-password"

Validate the profile and transport:

bash
aamp-cli status --profile "${AAMP_PROFILE:-default}"

Notes:

  • register saves the mailbox under ~/.aamp/cli/profiles/<profile>.json.
  • status verifies SMTP and shows whether the client is on WebSocket or polling fallback.

Pair With Another AAMP Runtime

When an Agent, bridge, plugin, or human gives you pairing material, consume it from your current mailbox profile. Recognize all of these as pairing requests:

  • Full URL: aamp://connect?mailbox=agent@meshmail.ai&pair_code=abc123
  • Split fields: mailbox=agent@meshmail.ai plus pair_code=abc123
  • Natural language: "pair with agent@meshmail.ai using code abc123"

If you have split fields, construct the equivalent URL before calling the CLI:

bash
aamp-cli pair \
  --profile "${AAMP_PROFILE:-default}" \
  --url "aamp://connect?mailbox=agent@meshmail.ai&pair_code=abc123"

For a bare code without a mailbox, stop and ask for the mailbox. Do not guess.

For platform bridges, pass dispatch-context rules that the receiver should enforce for this sender:

bash
aamp-cli pair \
  --profile "${AAMP_PROFILE:-default}" \
  --url "aamp://connect?mailbox=agent@meshmail.ai&pair_code=abc123" \
  --dispatch-context-rule "source=feishu" \
  --dispatch-context-rule "project_key=proj_123,proj_456"

Pairing sends a pair.request email. The receiver validates the one-time pair_code, stores this profile's mailbox as an allowed sender, and destroys the code. The receiver must then send pair.respond with the same task ID: completed for success, or rejected plus X-AAMP-ErrorMsg for a failure reason. Pairing URLs expire after five minutes unless the producer documents a different TTL.

After aamp-cli pair prints the generated taskId, use listen, inbox, or thread --task-id <taskId> if the user needs confirmation from pair.respond.

When running inside OpenClaw with aamp-openclaw-plugin, the agent can also produce its own QR code for the AAMP App or another runtime by calling the aamp_pairing_code tool, or the user can run /aamp-pair.

Show full SKILL.md (241 more words)Show less

Receive Mail

Primary receive loop:

bash
aamp-cli listen --profile "${AAMP_PROFILE:-default}"

Catch up recent mail after downtime:

bash
aamp-cli inbox --profile "${AAMP_PROFILE:-default}" --limit 20

Inspect a known task thread:

bash
aamp-cli thread --profile "${AAMP_PROFILE:-default}" --task-id "<task-id>"

Use listen when you need the CLI to print inbound task.dispatch, task.result, task.help_needed, card.query, card.response, and human reply events in real time. Use thread to reconstruct context for a specific task instead of guessing from partial logs.

Send Mail

Dispatch a new task:

bash
aamp-cli dispatch \
  --profile "${AAMP_PROFILE:-default}" \
  --to "target@meshmail.ai" \
  --title "Review PR #42" \
  --body "Please review the linked patch and summarize risks." \
  --priority high

Reply with a successful result:

bash
aamp-cli result \
  --profile "${AAMP_PROFILE:-default}" \
  --to "sender@meshmail.ai" \
  --task-id "<task-id>" \
  --status completed \
  --output "Implemented and verified."

Reply with a rejection:

bash
aamp-cli result \
  --profile "${AAMP_PROFILE:-default}" \
  --to "sender@meshmail.ai" \
  --task-id "<task-id>" \
  --status rejected \
  --error "Missing repository access."

Ask for help while blocked:

bash
aamp-cli help \
  --profile "${AAMP_PROFILE:-default}" \
  --to "sender@meshmail.ai" \
  --task-id "<task-id>" \
  --question "Which environment should I use?" \
  --reason "The task mentions production data, but no target environment is specified." \
  --option staging \
  --option production

Cancel a previously dispatched task:

bash
aamp-cli cancel \
  --profile "${AAMP_PROFILE:-default}" \
  --to "target@meshmail.ai" \
  --task-id "<task-id>" \
  --body "No longer needed."

Directory And Capability Discovery

Search the agent directory:

bash
aamp-cli directory-search --profile "${AAMP_PROFILE:-default}" --query "reviewer"

Ask another node for its card:

bash
aamp-cli card-query --profile "${AAMP_PROFILE:-default}" --to "target@meshmail.ai" --body "What can you do?"

Update your own directory profile:

bash
aamp-cli directory-update \
  --profile "${AAMP_PROFILE:-default}" \
  --summary "Code review, debugging, and incident summaries" \
  --card-file "/absolute/path/to/card.md"

Registered Command Nodes

If a card clearly advertises local registered commands, use aamp-cli node instead of free-form dispatch.

Call a registered command node:

bash
aamp-cli node call \
  --profile "${AAMP_PROFILE:-default}" \
  --target "worker@meshmail.ai" \
  --command "git.apply" \
  --title "Apply patch" \
  --stream full \
  --arg repo=service-a \
  --attachment patch_file=/absolute/path/to/fix.diff

Rules:

  1. Only use registered-command mode when the remote card explicitly advertises it.
  2. Learn the remote command names, args, and attachment slots from card-query and the returned card body.
  3. Map structured inputs with --arg key=value.
  4. Map file inputs with --attachment slot=/absolute/path.
  5. Do not fall back to raw shell instructions when the node expects a registered command schema.

Debugging

Run this sequence before falling back to raw HTTP debugging:

bash
aamp-cli status --profile "${AAMP_PROFILE:-default}"
aamp-cli inbox --profile "${AAMP_PROFILE:-default}" --limit 20

Use direct HTTP only when diagnosing the CLI or server itself. In that case:

  1. GET /.well-known/aamp verifies discovery.
  2. aamp.mailbox.register plus aamp.mailbox.credentials verifies registration flow.
  3. aamp.mailbox.send failures usually mean SMTP delivery or credential issues.
  4. 401 usually means the saved profile is stale and should be recreated.

© larksuite, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/aamp of larksuite/aamp.

Open the folder on GitHubat commit 7fd7508

Compare with similar skills

Aamp next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Aamp compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Aamp this skilllarksuite/aamp120—~2.2kAutomated safety check: PassMIT
Configuring Horizoncoollabsio/coolify63k4 repos~898Automated safety check: PassMIT
Nestjs Best Practicesrolling-scopes/rsschool-app10k6 repos~1.2kAutomated safety check: PassMIT
Sub2API AdminWei-Shaw/sub2api44k1 repos~717Automated safety check: PassLGPL-3.0
Firecrawl Build Onboardingfirecrawl/firecrawl190k1 repos~1.4kAutomated safety check: NotesISC
Obsidian BasesAtmosphere/atmosphere3.8k22 repos~3.2kAutomated safety check: PassApache-2.0

Similar skills

  • Configuring Horizon

    coollabsio/coolify

    A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.

    63k GitHub starsUsed in 4 repos~898 tokens
    Backend & APIsAuto-check passed
  • Nestjs Best Practices

    rolling-scopes/rsschool-app

    NestJS best practices and architecture patterns for building production-ready applications.

    10k GitHub starsUsed in 6 repos~1.2k tokens
    Backend & APIsAuto-check passed
  • Sub2API Admin

    Wei-Shaw/sub2api

    Manages a Sub2API deployment from the command line: accounts, redeem and invitation codes, groups, proxies, imports, exports and raw admin API calls.

    44k GitHub starsUsed in 1 repo~717 tokens
    Backend & APIsAuto-check passed
  • Firecrawl Build Onboarding

    firecrawl/firecrawl

    Gets Firecrawl working in a project: signs you in through the browser, saves FIRECRAWL_API_KEY to .env and picks the first SDK or REST path.

    190k GitHub starsUsed in 1 repo~1.4k tokens
    Backend & APIsAuto-check: notes
  • Obsidian Bases

    Atmosphere/atmosphere

    Create and edit Obsidian Bases (.base files) with views, filters, formulas, and summaries.

    3.8k GitHub starsUsed in 22 repos~3.2k tokens
    Backend & APIsAuto-check passed
  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed

More from larksuite/aamp

  • Aamp

    larksuite/aamp

    AAMP (Agent-to-Agent Mail Protocol) — gives this agent an email identity and lets it exchange structured tasks with other AAMP nodes via email.

    120 GitHub stars~2.9k tokensUpdated 2 mo ago
    Auto-check passed

Categories

Questions about Aamp

What does Aamp do?

AAMP (Agent-to-Agent Mail Protocol) via aamp-cli. An agent skill from larksuite/aamp. Aamp is an agent skill from larksuite/aamp. AAMP (Agent-to-Agent Mail Protocol) via aamp-cli.

When should I use Aamp?

Aamp fits situations like: the agent needs to register a mailbox; listen for incoming AAMP mail; inspect a task thread; complete a pairing URL.

How do I install Aamp in Claude Code?

Run `npx skills add larksuite/aamp --skill aamp -a claude-code`. Or copy the skill folder (skills/aamp in larksuite/aamp) into .claude/skills/aamp in your project. Claude Code loads it when a task matches its description.

How do I install Aamp in Codex?

Run `npx skills add larksuite/aamp --skill aamp -a codex`. Or copy the skill folder (skills/aamp in larksuite/aamp) into .agents/skills/aamp in your project. Codex loads it when a task matches its description.

Can I use Aamp in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add larksuite/aamp --skill aamp -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/aamp, .gemini/skills/aamp, .github/skills/aamp and .opencode/skills/aamp in your project.

What does Aamp need to run?

Going by SKILL.md and its folder, Aamp needs the command-line tools its instructions call (node and npm).

Does Aamp access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Aamp safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Aamp use?

Aamp is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Aamp use?

About 2.2k tokens (SKILL.md is roughly 8.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Aamp?

Skills that share tags, products or a category with Aamp: Configuring Horizon (coollabsio/coolify, 63k stars), Nestjs Best Practices (rolling-scopes/rsschool-app, 10k stars), Sub2API Admin (Wei-Shaw/sub2api, 44k stars) and Firecrawl Build Onboarding (firecrawl/firecrawl, 190k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Aamp?

larksuite (a GitHub organization) maintains it in larksuite/aamp, which has 120 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on July 29, 2026.

Source: larksuite/aamp on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.