Skip to content
Documentation: Installing with rmk

Installing with rmk

How items get into your AI tools, and how to keep them current.

From the Documentation in Ronne AI Marketplace 0.3.0.

What rmk does

rmk is Ronne AI Marketplace's command-line tool. It installs items from this marketplace into a project, or into your home folder, writing each AI tool's own files, and keeps them up to date. Every item's Overview shows its commands, with a quick --target for each tool it works in:

rmk install @platform/secure-coding
rmk install @platform/[email protected]

It records what it installed in a lockfile, so everyone on the project gets the same versions, and it never overwrites a file or setting you wrote yourself. Nothing from an item runs at install time: hooks and scripts are written, not run.

rmk --help lists every command, and --json makes any of them answer with one JSON object, for scripts and agents.

It also works the other way: rmk export sends an item you wrote in your AI tool to this marketplace as a draft. Exporting your own items.

Getting rmk

rmk is on npm as @ronneai/rmk (the unscoped name was taken; the command is still rmk). It needs Node.js 22.12 or later:

npm install --global @ronneai/rmk
rmk --version

npm update --global @ronneai/rmk gets a newer release. If you built it from a copy of the repository before and linked it, unlink that first (npm unlink --global @ronneai/rmk), so the npm install is the rmk you run. Contributors can still run it from a copy of the repository: after pnpm install and pnpm build, it's node packages/cli/dist/bin.js.

Logging in

rmk login --registry https://ronne.example

It asks for your email and password, and stores a token for this registry in ~/.config/rmk/config.json, readable by you alone. With a token made under Access tokens, or in CI, use rmk login --token rmk_…, or set RMK_TOKEN and RMK_REGISTRY. RMK_TOKEN only goes to a registry you chose (RMK_REGISTRY, --registry, your default, or one you logged in to), never to one only a project's rmk.config.json or rmk.lock names: rmk stops with token_withheld instead. rmk whoami says who you are, at which registry, and why that one; rmk logout revokes the token.

You can be logged in to several registries at once. Each command uses the first it finds:

  1. --registry on the command line;
  2. RMK_REGISTRY;
  3. the project's: registry in rmk.config.json, else in rmk.lock. rmk install records it, so a project keeps its registry, and teammates use it too;
  4. your default: the registry you last logged in to with --registry.

To move a project to another registry, run rmk install --registry <url>: it updates both files.

The token only travels over https, except to localhost.

Installing

rmk install @platform/code-reviewer          # latest
rmk install @platform/code-reviewer@^1.4.0   # a range
rmk install @platform/code-reviewer@next     # a tag
rmk install                                  # exactly the lockfile
  1. Target. Which AI tools: --target claude-code, codex, cursor, several (claude-code,cursor), the targets in rmk.config.json, or what the project looks like it uses. rmk platforms lists the tools and what each supports; a type a tool can't take is a warning, and the rest carries on.
  2. Resolve. The registry picks one version of each item, dependencies included, as Dependencies explains.
  3. Download and check. Each package's checksum is checked before anything is written; a mismatch stops the install. A version already in rmk.lock must also have the checksum recorded there, since a released version never changes: if the registry gives other bytes for it, rmk stops (checksum_mismatch). To accept them anyway, remove the item from rmk.lock (in user scope, ~/.config/rmk/user.lock).
  4. Write. The files each tool reads, then the lockfile and the state file. Deprecated versions print their message, and MCP servers list the environment variables you still have to set.

rmk install with nothing after it installs exactly what the lockfile holds, so a teammate gets the same files. --scope user installs into your home folder instead of the project.

Keeping items up to date

rmk outdated
rmk update                    # everything, within its ranges
rmk update @platform/code-reviewer
rmk remove @platform/code-reviewer
  • rmk outdated shows, for each item you asked for, the version locked, the newest its range allows, and the newest published.
  • rmk update moves items to the newest version their ranges allow, and rewrites their files. Items you don't name stay where they are.
  • rmk remove deletes an item's files and settings, and those of any dependency nothing else needs.
  • rmk list shows what the project asks for; rmk list --installed what the lockfile holds.

The files it writes

FileWhat it holdsCommit it?
rmk.config.jsonWhat you asked for: each item with its range or tag, the targets, and the registry.Yes
rmk.lockWhat was resolved: one version and checksum per item.Yes
.rmk/state.jsonEvery file and setting rmk wrote, with a hash, so it can update or remove exactly those.Yes: a teammate's rmk needs it to know what it owns.
~/.config/rmk/Your token, and the lockfile and state for home-folder installs.No

Downloads are cached under ~/.cache/rmk/, by checksum.

Your own edits

Every file rmk writes carries a managed by rmk marker, and every setting it adds is tracked in the state file. Before it changes or removes one, it checks that the file or setting is still what it wrote.

  • A file or setting rmk didn't write is never touched. If an install would need its place, that's a conflict: rmk stops, lists them, and exits with code 3.
  • One you edited since rmk wrote it is a conflict too, on update and on removal.
  • --force replaces them; otherwise move them aside and run again.
  • One you deleted is taken as removed on purpose: rmk forgets it, and writes it again only when you install or update.

To send your edits back to the item, run rmk export: an edited install becomes a change proposal to the version you installed.

Tokens and the API

rmk and the registry's MCP server read the registry through its API, with a personal access token. You make one under Access tokens in your account, or rmk login makes one for you. A token acts as you: it can read everything published, search, and download items, and it can create drafts in your name. It can't sign in to this website, and you can revoke it at any time.

curl -H 'Authorization: Bearer rmk_…' \
  https://ronne.example/api/v1/items?q=security

Each download of an item, as rmk install makes, counts as one install. Every card in the catalogue and on the home page shows the count, the home page ranks Most used by it, and the catalogue's Sort can put the most installed first. Nothing about who installed it is stored.

A draft created with a token (POST /api/v1/drafts, with its files) is like one you start here: only you see it, under Submissions, and nothing reaches a reviewer until you submit it. A token can create drafts while you have fewer than 50 (submit or delete some to make room), and update your own drafts (PUT /api/v1/drafts/…), at most 30 uploads in 10 minutes. It can also submit your drafts for review (rmk submit), which reviewers then see. Each upload and each submit is written to the audit log with the token's name and the draft's name, which root can read; its files aren't.

The registry MCP server, rmk-mcp, uses the token rmk login saved, or RMK_TOKEN: it can do what the token can, and never shows it.

Your AI tools

rmk writes for one AI tool or several. Each tool has its own page: where every type of item goes, and what to know before the tool uses it.

ToolTargetPicked up when the project has
Claude Codeclaude-code.claude/ or CLAUDE.md
Codexcodex.codex/
Cursorcursor.cursor/

With one tool picked up, rmk uses it; with several, it asks, or you say which with --target. --target claude-code,codex writes for both, and a file two tools read is written once and recorded for both. rmk platforms lists every tool and what it supports.

Before you install, an item's page says on its Works in tab which of these tools it goes to, and where: supported, partly, turned off by the item's own ronne.yaml, or skipped. The catalogue's Filters (Works in) list the items one tool takes, as does rmk search <query> --target codex, and rmk info prints each tool's level for a version.

From inside your AI tool

You can also ask your AI tool to search and install items, through the registry MCP server, rmk-mcp: it shows you a plan first, then writes exactly that, as rmk would. It can export an item you wrote as a draft the same way. Registry MCP server explains how to set it up and what it can do.

As plugins

Claude Code can also install this marketplace's items itself, as plugins, from /plugin. Two commands set that up:

  • rmk plugin-setup claude-code adds this marketplace to Claude Code's settings (--scope project for the project's, --remove to take it out). Like every setting rmk writes, it never replaces an entry you made or edited.
  • rmk auth headers prints your token as an Authorization header, and nothing else. Claude Code runs it to read the marketplace; you don't need to.

For Codex and Cursor, which add marketplaces only from git repositories, rmk feed build --out <folder> writes this marketplace's plugins as a repository to commit and push, and --print-workflow github or gitlab prints a CI file that keeps it current.

Plugin marketplaces explains these, and when to use plugins rather than rmk install.

Usage reporting

When the instance collects usage, rmk sends it daily counts of installs, removals and runs of the items it installed, and says so the first time. rmk telemetry status shows each instance's policy, and rmk telemetry off stops it where people may choose. Usage data says exactly what is sent.