.llmwiki/profile.json.
They do not run code and do not change the runtime profile loader.
List templates
default profile plus installable templates such
as autosci and newsroom.
Inspect a template
Install a built-in template
.llmwiki/profile.json does not exist.
On success, the command writes .llmwiki/profile.json and then attempts to write
the advisory .llmwiki/template-lock.json sidecar. If only the lock write fails,
the profile remains installed and the command prints a warning.
Install a local template file
Replace an existing profile
--force only replaces a profile when the typed corpus is empty. Existing pages,
relations, artifacts, workflow runs, event records, pending or archived review
candidates, or unresolved typed-store problems cause a refusal.
llmwiki template init default never writes a profile. The default profile is
already active when .llmwiki/profile.json is absent.
Manage remote taps
tap add, tap list, and tap remove do not access the network. tap remove
disables the source and retains its key, sequence, publisher pins, revocations,
and coordinate history.
tap forget is the destructive recovery path for a lost root key, moved
infrastructure, or exhausted continuity store. It permanently deletes that
tap’s roots, publisher pins, revocations, and coordinate history, making a
later add equivalent to trusting the source fresh. It requires --yes.
Search signed indexes
stale and cannot introduce unseen coordinates.
An unrefreshed or unavailable tap does not hide verified results from healthy
taps: unscoped search returns those results plus a warning for each skipped
tap. Search explicitly scoped with --tap remains fail closed.
Inspect or verify a remote coordinate
Install a signed remote release
Remote installs require an exact qualified coordinate:--yes only after
reviewing those values in automation:
--yes refuses without writing. The
package is reverified from accepted cached evidence under the project and tap
state locks before installation. Network I/O never occurs while those locks are
held.
Check installed status
interrupted-write. Run llmwiki recover, or retry the update or compile, to
restore the recorded pre-update profile and provenance before continuing.
Preview or apply a remote update
Author and publish a tap
Publishers use these commands to create keys, sign packages, and build a distribution. Everything runs offline; nothing is uploaded.init creates separate Ed25519 tap and publisher keypairs under my-tap/keys/
(mode 0600 on POSIX; Windows access is governed by filesystem ACLs),
never printing or overwriting a private key, and prints each public key’s fingerprint.
add validates the package with the production validator, signs its claim, and records
the coordinate as immutable: the same coordinate may never resolve to different bytes.
build advances the sequence, signs the index, writes packages before the index, and
verifies the whole tree as a consumer would before publishing it. The sequence commits
last, so a failed build leaves the workspace unchanged and a retry is a clean re-run. The
output must live outside the workspace — otherwise it would publish your private keys. Pass
--refresh to renew an expiring index under a fresh lifetime, or --force to republish when
nothing else changed.
Rotate and revoke
build, because a rotation
claim carries the sequence of the index that publishes it and that sequence is only known
at build time.
A publisher-key rotation re-signs every package with the successor key: a package signed by
a retired key stops verifying once the index announces its successor. Payloads and
content-addressed filenames never change. Revoking the active publisher key requires
rotating to a successor in the same build.
Verify a publisher distribution offline
Publishers use this before uploading a built tap. It reads a static distribution directory, verifies it exactly as a client verifies downloaded bytes, and writes nothing. It never reaches the network.--key-file from
the channel through which you distribute the tap key, not from inside the
directory being verified: a key carried by the tree it verifies proves only
self-consistency.
Success prints bounded provenance (add --json for the same result as an object)
and exits 0:
rotations or a tapKeyRotation is refused, because a rotation chain is only
meaningful against a client’s previously pinned key. Verify those from a clean
client that already pinned the old key.
Tap operators and template publishers can follow Publish a signed template
tap for the protocol and release workflow.